CVE-2026-5865 is a high-severity type confusion vulnerability in the V8 JavaScript and WebAssembly engine used by Google Chrome before version 147.0.7727.55. A remote attacker can trigger the flaw by serving crafted HTML content that causes V8 to mishandle an object’s runtime type, potentially resulting in arbitrary code execution within the browser’s sandboxed renderer context.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
1 valid exploit after Mallory filtered fakes, detection scripts, and README-only repos.
Single-file JavaScript exploit (exploit.js) implementing a full memory-corruption-to-code-execution chain against a vulnerable V8-like JavaScript runtime. The code is not a framework module and is clearly an exploit rather than a detector. Repository structure is minimal: one JavaScript file containing helper conversions (float/int reinterpretation), heap grooming, corruption trigger logic, exploitation primitives, and final payload delivery. The script first warms up a function (`blah`) to influence optimization/JIT behavior, performs garbage collection and heap spraying with crafted arrays, and then triggers type confusion/object corruption so that `obj.x` becomes a forged array-like object. From that corrupted state, the exploit builds classic exploitation primitives: 1. `addrof(v)`: leaks the address of a JavaScript object. 2. `fakeobj(addr)`: materializes a fake JS object from a chosen address. 3. Weak arbitrary read/write: forges a fake double array and retargets its elements pointer. 4. Strong arbitrary read/write: locates ArrayBuffer backing store fields and repoints an attacker-controlled DataView for reliable 64-bit memory access. After validating both weak and strong memory primitives, the exploit creates a small WebAssembly module and instance. It then walks internal WebAssembly structures (`trusted_data`, `jump_table_start`) to locate executable code memory. Finally, it overwrites the wasm code entry with hardcoded x86-64 shellcode containing the string `/bin/sh`, prints a status message, and invokes the wasm export to execute the payload. There are no network callbacks, URLs, IPs, or C2 endpoints. The only concrete endpoint-like artifact is the local executable path `/bin/sh`. This is a local/native code execution exploit, though the same bug class could potentially be browser-relevant if adapted to a browser embedding of V8. The exploit is operational because it includes a complete hardcoded payload and end-to-end exploitation logic, but it is not obviously weaponized as a reusable framework component.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
14 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A publicly recorded, fixed vulnerability affecting Chromium; no vulnerability type or impact details are provided.
A high-severity type confusion vulnerability in Chrome's V8 engine.
A high-severity type confusion vulnerability in V8.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.