CVE-2026-1862Patch(apple / chrome)

LOWCVSS 8.8 · HIGH

Exploit discussion active in current signal (1 latest mentions)

Immediate actions

  • Patch apple chrome systems immediately
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft

Recommended action window: High priority (within 72h)

NVD description

Type Confusion in V8 in Google Chrome prior to 144.0.7559.132 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)

3.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-843

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

DECLINING

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • chrome
  • linux_kernel
  • macos
  • windows

Threat summary

  • Public PoC is present in monitored signal
  • Patch or workaround signal is available
  • 17 mentions across 7 observed days
  • Momentum state: declining

What's happening

  • PoC mentioned or linked in 1 signal
  • Patch or workaround mentioned in 10 signals
  • Technical details provided in 13 signals
  • Disclosure: 5 classified signals
  • General: 3 classified signals
  • Peaked 5d ago at 7 mentions (2026-02-04); latest day: 1
  • 17 total mentions across 7 days

Affected systems

Products
chromelinux_kernelmacoswindows

1 version affected across 4 products

Deep dive

Activity timeline17 mentions / 7d
02457Mentions · 2026-02-03: 1Mentions · 2026-02-04: 7Mentions · 2026-02-05: 2Mentions · 2026-02-06: 4Mentions · 2026-02-08: 1Mentions · 2026-02-09: 1Mentions · 2026-02-10: 1PoC Mentioned / Linked · 2026-02-06: 1Patch / Workaround · 2026-02-04: 4Patch / Workaround · 2026-02-05: 2Patch / Workaround · 2026-02-06: 2Patch / Workaround · 2026-02-08: 1Patch / Workaround · 2026-02-09: 1Technical Details · 2026-02-03: 1Technical Details · 2026-02-04: 5Technical Details · 2026-02-05: 2Technical Details · 2026-02-06: 2Technical Details · 2026-02-08: 1Technical Details · 2026-02-09: 1Technical Details · 2026-02-10: 102-0302-0402-0502-0602-0802-0902-10
Signal classification4 categories
Patch
847.1%
Disclosure
529.4%
General
317.6%
PoC
15.9%
Referenced assets12 URLs
Classification over time
DateTotalLabels
2026-02-031
Disclosure1
2026-02-047
Disclosure2General1Patch4
2026-02-052
Patch2
2026-02-064
General2Patch1PoC1
2026-02-081
Patch1
2026-02-091
Disclosure1
2026-02-101
Disclosure1
Full discourse17 posts
  • Shreyas Penkar@streypaws
    PoC

    Wrote a Trigger PoC to Leak Hole Value for CVE-2026-1862 (A Type Confusion in Chrome V8) reported by @ret2happy just a week ago (and showed up in Chrome releases 3 days ago). Will release the PoC (and a blog maybe if I get time 😅) once patches roll out to most systems. https://t.co/q7o1QSB3KS

    Post summary

    The author has written a PoC for CVE-2026-1862 (a type confusion bug in Chrome V8) and plans to publish it once patches are widely available.

    3100124408.3K
    602 followersView on X
  • xvonfers@xvonfers
    Disclosure

    (CVE-2026-1862)[479726070][maglev]Type Confusion https://chromium-review.googlesource.com/c/v8/v8/+/7534881 Reported by Chaoyuan Peng (@ret2happy)

    Post summary

    The post announces the discovery of CVE‑2026‑1862, a type‑confusion issue in V8, and links to the Chromium review where the fix is discussed, without providing PoC, exploit details, or evidence of active exploitation.

    75041173.0K
    4.8K followersView on X
  • @Welsh ICP Conviction@ICPLEGEND1966
    Disclosure

    Another @googlechrome Security Alert — Meanwhile $ICP ♾️ by @dfinity Runs Verifiable Apps On-Chain Without Trusting the Browser. Facts Google disclosed two high-severity Chrome vulnerabilities (Feb 2026): CVE-2026-1861: Heap buffer overflow in libvpx video codec. CVE-2026-1862: Type confusion in the V8 JavaScript engine. Patches are released gradually. Fix only activates after the user restarts the browser. Chrome has ~3 billion users, making it the largest consumer attack surface. Structural reality of Web2 This is not an isolated event. It is how the current web works: Code executes on user devices. Security depends on: Patch cycles User restarts Trusted backends Invisible server updates. A single browser flaw can expose billions of endpoints. How $ICP by @dfinity is different $ICP changes the execution model of the web. On ICP: Applications run on-chain, not on local servers. Code is: Deterministic Verifiable Tamper-resistant Frontend and backend logic can both live on-chain. Users receive cryptographically certified responses. Result: No hidden server logic. No silent backend changes. Reduced trust in opaque infrastructure. Security model comparison Traditional Web2 Local browser execution Centralized servers Frequent critical CVEs Trust-based compute User-dependent patching $ICP On-chain compute, Verifiable execution Single canonical app state, Cryptographic response certification, Reduced trust assumptions. Bottom line Browser security alerts will keep happening. That is inherent to the client-side Web2 model. ICP represents a different architecture: Verifiable compute On-chain applications Reduced reliance on trust and patch cycles Security patches treat symptoms. Verifiable on-chain compute changes the system. $ICP ♾️ by @dfinity

    Post summary

    Google disclosed two high‑severity Chrome vulnerabilities (CVE‑2026‑1861: heap buffer overflow in libvpx; CVE‑2026‑1862: type confusion in V8), with patches being released gradually and requiring a browser restart to take effect.

    130250722
    1.2K followersView on X
  • عالم التكنولوجيا@Q8Pro
    General

    @Darksweet1984 ثغرة الأخطر CVE-2026-1862 الثغرة المسؤولة عن تشفير CVE-2026-1861

    Post summary

    The tweet merely references two CVE identifiers without providing any additional detail, evidence of exploitation, or remediation information.

    010352.6K
    629.8K followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-1862 Type Confusion in V8 in Google Chrome prior to 144.0.7559.132 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium securi… https://www.cve.org/CVERecord?id=CVE-2026-1862

    Post summary

    The text announces CVE-2026-1862, a type confusion flaw in V8 that can lead to heap corruption when processing crafted HTML in Google Chrome before version 144.0.7559.132, with no PoC, exploit code, patch, or active exploitation discussed.

    01030290
    56.5K followersView on X
  • VulnTracker@vuln_tracker
    General

    @streypaws @ret2happy You now can see the full detail about CVE-2026-1862 from https://vulntracker.io/cves/CVE-2026-1862 for FREE

    Post summary

    The tweet simply directs readers to a website where full details about CVE-2026-1862 can be accessed; it does not provide additional technical or exploit information.

    00020184
    333 followersView on X
  • VulnTracker@vuln_tracker
    Patch

    🚨 New #Chrome security updates patch critical vulnerabilities that could let attackers execute arbitrary code or crash systems — including heap buffer overflow and type confusion flaws. Stay on top of threats like CVE-2026-1862 & CVE-2026-1861 and hundreds more with VulnTracker! 👉For full details about these CVEs, check out: https://vulntracker.io/dashboard?date_type=updated #cybersecurity #infosec #vulnerability #vulnerabilitytracking #Chrome #zeroday #vulnerabilityintelligence

    Post summary

    Chrome security updates patch critical vulnerabilities such as CVE-2026-1862 and CVE-2026-1861, addressing heap buffer overflow and type confusion flaws. Further details are available via the provided VulnTracker link.

    00020197
    333 followersView on X
  • CERT-PY@CERTpy
    General

    ⚠️ Vulnerabilidades en Google Chrome ❗ CVE-2026-1862 ❗ CVE-2026-1861 ➡️ Más info: https://www.cert.gov.py/vulnerabilidades-en-google-chrome-13/ https://t.co/McEcGcqJKG

    Post summary

    The post merely lists two Google Chrome CVEs without providing any technical details, exploitation status, or mitigation information.

    01000158
    6.6K followersView on X
  • ThreatSynop@ThreatSynop
    Patch

    🚨 Google Patches High-Severity Chrome Flaws (CVE-2026-1861, CVE-2026-1862) That Could Enable RCE or Crashes Google shipped a Chrome Stable update (144.0.7559.132/.133) fixing two high-severity memory-corruption issues—heap buffer overflow in libvpx (CVE-2026-1861) and type confusion in V8 (CVE-2026-1862)—that could be triggered by malicious web content to crash the browser or potentially enable code execution. 🎯 Target: Global/Chrome Users #️⃣ Category: #Vulnerability #BlueTeam 🔗 URL: https://www.techrepublic.com/article/news-google-chrome-security-update-february-2026/

    Post summary

    Google released a Chrome update that patches two high‑severity CVEs that could allow remote code execution or crashes; no PoC, exploit, or active exploitation is reported.

    0000174
    191 followersView on X
  • ThreatSynop@ThreatSynop
    Patch

    🚨 Chrome 144 emergency update patches two “High” bugs enabling code execution and browser crashes Google pushed Chrome 144.0.7559.132/.133 to fix CVE-2026-1862 (V8 type confusion) and CVE-2026-1861 (libvpx heap buffer overflow), where a user visiting a crafted site/video can trigger memory corruption that may lead to renderer-level arbitrary code execution or DoS—update now as details remain restricted until most users patch. 🎯 Target: Global/Chrome Users #️⃣ Category: #Vulnerability #BlueTeam 🔗 URL: https://cybersecuritynews.com/chrome-vulnerabilities-arbitrary-code-2/

    Post summary

    The tweet announces an emergency update to Chrome 144 to patch CVE-2026-1862 and CVE-2026-1861, which could allow renderer-level arbitrary code execution or DoS, urging users to apply the update immediately.

    0001070
    192 followersView on X
  • VulDB 🛡@vuldb
    Disclosure

    There is a new vulnerability with elevated criticality in Google Chrome (CVE-2026-1862) https://vuldb.com/?id.344166

    Post summary

    A new high‑criticality vulnerability (CVE‑2026‑1862) affecting Google Chrome has been disclosed, with details available on VulDB.

    0000178
    2.1K followersView on X
  • Ferramentas Linux@Cezar_H_Linux
    Patch

    URGENT: #Fedora 43 Chromium update patches critical RCE flaws: heap overflow in libvpx (CVE-2026-1861) and type confusion in V8 (CVE-2026-1862). Exploitable via crafted HTML. Read more: 👉 https://tinyurl.com/5j2hba73 #Security https://t.co/7kKAy8K0Hb

    Post summary

    Fedora 43 Chromium update patches two critical RCE vulnerabilities—heap overflow in libvpx (CVE-2026-1861) and type confusion in V8 (CVE-2026-1862). No active exploitation or PoC was reported.

    0000076
    1.3K followersView on X
  • 【學】@manabu2111
    Patch

    CVE-2026-1862、Type Confusion in V8、 この脆弱性は、同じく「Chromium」をベースとする「Google Chrome」でも先日修正済み

    Post summary

    The post references CVE-2026-1862, a type‑confusion vulnerability in V8, and notes that Google Chrome has already applied a fix.

    0000054
    2.2K followersView on X
  • Brumaire William Boamson@williamboamson
    Patch

    Google corrige 2 failles critiques dans Chrome (CVE-2026-1862, CVE-2026-1861) permettant exécution de code arbitraire ou crash via sites malveillants. Mettez à jour vers Chrome 144.0.7559.132 + dès maintenant. #chevalyeTek https://t.co/ua9Sb9oRCp

    Post summary

    Google released an update to fix two critical Chrome vulnerabilities that could enable arbitrary code execution or crashes through malicious websites; users are urged to update immediately.

    0000065
    90 followersView on X
  • PulsePatch.io@pulsepatchio
    Disclosure

    A Type Confusion vulnerability (CVE-2026-1862) in Chromium's V8 engine may allow heap corruption via crafted HTML. Users should monitor for official updates. #Chromium #V8 #infosec https://www.pulsepatch.io/posts/cve-2026-1862-chromium-v8-type-confusion

    Post summary

    The post announces CVE-2026-1862, a type confusion vulnerability in Chromium's V8 engine that may allow heap corruption through crafted HTML, and urges users to watch for vendor updates.

    0000080
    1 followersView on X
  • ThreatSynop@ThreatSynop
    Patch

    🚨 Chrome 144 emergency update fixes two high-severity memory bugs enabling crashes and potential code execution Google released Chrome 144.0.7559.132/.133 to patch CVE-2026-1861 (libvpx heap buffer overflow) and CVE-2026-1862 (V8 type confusion), both memory-corruption flaws that can be triggered via crafted web content and could be weaponized for arbitrary code execution or browser instability. Update immediately as full technical details remain restricted until most users are patched. 🎯 Target: Global/Chrome Users #️⃣ Category: #Vulnerability #BlueTeam 🔗 URL: https://cyberpress.org/chrome-vulnerabilities/

    Post summary

    Google issued an emergency Chrome 144 update to patch two high-severity memory bugs (CVE-2026-1861 and CVE-2026-1862) that could enable crashes or code execution via crafted web content. The focus is on the availability of the patch and the technical nature of the flaws.

    0000071
    192 followersView on X
  • 【學】@manabu2111
    Patch

    「Google Chrome」に2件の脆弱性、「libvpx」「V8」の欠陥を修正 - 窓の杜 https://forest.watch.impress.co.jp/docs/news/2083222.html 、本リリースでは、以下の2件の脆弱性が修正、 CVE-2026-1861、Heap buffer overflow in libvpx、 CVE-2026-1862、Type Confusion in V8、 深刻度の評価は、いずれも4段階中上から2番目の「High」

    Post summary

    Google Chrome released a patch fixing two high‑severity CVEs—CVE‑2026‑1861 in libvpx (heap buffer overflow) and CVE‑2026‑1862 in V8 (type confusion).

    0000051
    2.2K followersView on X
CPE platform detail4 entries

4 of 4 entries

PartVendorProductVersionTarget SWTarget HW
OSapplemacos---
Appgooglechrome---
OSlinuxlinux_kernel---
OSmicrosoftwindows---

Explore more