Description
Object corruption in V8 in Google Chrome prior to 146.0.7680.178 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)
Published: 2026-04-01
Score: 8.8 High
EPSS: < 1% Very Low
KEV: No
Impact: Remote Code Execution
Action: Immediate Patch
AI Analysis

Impact

A defect in the V8 JavaScript engine of Google Chrome caused object corruption that lets an attacker run arbitrary code inside the browser process sandbox. The bug is categorized under memory corruption and type confusion weaknesses, which can lead to code execution on the client machine. Although the attacker gains code execution only within the sandboxed environment, any successful exploit could provide a foothold that may be leveraged for further attacks if the sandbox is subsequently broken or used to execute additional malicious payloads. This bifurcation of memory safety violations is most consistent with the listed weaknesses of CWE‑120 and CWE‑843.

Affected Systems

The vulnerability affects all desktop editions of Google Chrome released before version 146.0.7680.178 on every major operating system, including macOS, Linux, and Windows, as indicated by the referenced Common Platform Enumeration strings. Users whose browsers remain on these legacy versions are at risk regardless of platform.

Risk and Exploitability

The flaw carries an overall CVSS score of 8.8, classifying it as high severity, yet its EPSS score is below 1 %, indicating a very low probability of being actively exploited in the wild at present. It is not listed in the CISA KEV catalog. The exploitation path requires a remote attacker to serve a crafted HTML page that a victim’s Chrome will render, which is a straightforward attack vector for malicious sites or phishing campaigns. No additional discovery or privileged access is needed once the user opens the page, making the vulnerability readily exploitable in typical web browsing scenarios.

Generated by OpenCVE AI on April 2, 2026 at 02:31 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Update Google Chrome to version 146.0.7680.178 or newer

Generated by OpenCVE AI on April 2, 2026 at 02:31 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Debian DSA Debian DSA DSA-6192-1 chromium security update
History

Thu, 02 Apr 2026 00:15:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 6.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:L'}

cvssV3_1

{'score': 8.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H'}


Wed, 01 Apr 2026 23:45:00 +0000

Type Values Removed Values Added
Title chromium-browser: Object corruption in V8
First Time appeared Apple
Apple macos
Google
Google chrome
Linux
Linux linux Kernel
Microsoft
Microsoft windows
Weaknesses CWE-120
CWE-843
CPEs cpe:2.3:a:google:chrome:*:*:*:*:*:*:*:*
cpe:2.3:o:apple:macos:-:*:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:-:*:*:*:*:*:*:*
cpe:2.3:o:microsoft:windows:-:*:*:*:*:*:*:*
Vendors & Products Apple
Apple macos
Google
Google chrome
Linux
Linux linux Kernel
Microsoft
Microsoft windows
References
Metrics threat_severity

None

cvssV3_1

{'score': 6.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:L'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}

threat_severity

Important


Wed, 01 Apr 2026 05:00:00 +0000

Type Values Removed Values Added
Description Object corruption in V8 in Google Chrome prior to 146.0.7680.178 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)
References

cve-icon MITRE

Status: PUBLISHED

Assigner: Chrome

Published:

Updated: 2026-04-02T03:55:49.957Z

Reserved: 2026-03-31T20:07:12.562Z

Link: CVE-2026-5279

cve-icon Vulnrichment

Updated: 2026-04-01T13:40:57.473Z

cve-icon NVD

Status : Modified

Published: 2026-04-01T05:16:01.200

Modified: 2026-04-02T00:16:24.443

Link: CVE-2026-5279

cve-icon Redhat

Severity : Important

Publid Date: 2026-03-31T00:00:00Z

Links: CVE-2026-5279 - Bugzilla

cve-icon OpenCVE Enrichment

Updated: 2026-04-02T20:18:22Z

Weaknesses