CVE-2026-4447Disclosure(apple / chrome)

LOWCVSS 8.8 · HIGH

Exploit discussion active in current signal (1 latest mentions)

Immediate actions

  • Patch apple chrome systems immediately
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft

Recommended action window: High priority (within 72h)

NVD description

Inappropriate implementation in V8 in Google Chrome prior to 146.0.7680.153 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)

3.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-693

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • chrome
  • linux_kernel
  • macos
  • windows

Threat summary

  • Public PoC is present in monitored signal
  • Patch or workaround signal is available
  • 6 mentions across 4 observed days
  • Momentum state: stable

What's happening

  • PoC mentioned or linked in 1 signal
  • Patch or workaround mentioned in 2 signals
  • Technical details provided in 3 signals
  • Disclosure: 2 classified signals
  • Exploit: 1 classified signal
  • Peaked 3d ago at 3 mentions (2026-03-20); latest day: 1
  • 6 total mentions across 4 days

Affected systems

Products
chromelinux_kernelmacoswindows

1 version affected across 4 products

Deep dive

Activity timeline6 mentions / 4d
01223Mentions · 2026-03-20: 3Mentions · 2026-06-06: 1Mentions · 2026-06-19: 1Mentions · 2026-07-25: 1PoC Mentioned / Linked · 2026-06-06: 1Patch / Workaround · 2026-03-20: 2Technical Details · 2026-03-20: 1Technical Details · 2026-06-19: 1Technical Details · 2026-07-25: 103-2006-0606-1907-25
Signal classification4 categories
Disclosure
233.3%
Patch
233.3%
Exploit
116.7%
General
116.7%
Referenced assets3 URLs
Classification over time
DateTotalLabels
2026-03-203
Disclosure1Patch2
2026-06-061
Exploit1
2026-06-191
Disclosure1
2026-07-251
General1
Full discourse6 posts
  • kqx@kqx_io
    Patch

    "Claude find a 0day, make no mistakes" CVE-2026-4447 https://chromereleases.googleblog.com/2026/03/stable-channel-update-for-desktop_18.html https://t.co/STxqnBvGs5

    Post summary

    The post references CVE‑2026‑4447, linking to a Chrome stable channel update that serves as a vendor patch, but it does not provide PoC, exploit code, or technical vulnerability details.

    745060526285.2K
    767 followersView on X
  • kqx@kqx_io
    Exploit

    Pwning V8CTF with a 0day in Chrome thanks to Phi untagging. Read here: https://kqx.io/post/cve-2026-4447/ https://t.co/eSpfeah7I4

    Post summary

    A 0‑day vulnerability (CVE-2026-4447) was exploited to win V8CTF in Chrome via Phi untagging, with further details linked in the post.

    33412108816.3K
    985 followersView on X
  • 0xor0ne@0xor0ne
    General

    Analysis of a Chrome V8 untagging vulnerability (CVE-2026-4447) (@kqx_io) https://kqx.io/post/cve-2026-4447/ #infosec https://t.co/ycWRzUT3HO

    Post summary

    The tweet directs to an analysis of CVE‑2026‑4447, a Chrome V8 untagging vulnerability, but does not provide proof‑of‑concept code, exploit details, active exploitation, patches, or false‑positive claims.

    03101739910.5K
    93.7K followersView on X
  • 0xor0ne@0xor0ne
    Disclosure

    Analysis of a Chrome V8 Maglev Phi untagging vulnerability (CVE-2026-4447) https://kqx.io/post/cve-2026-4447/ Credits @kqx_io #infosec https://t.co/fPhqJ0hPJ7

    Post summary

    This post links to an analysis of CVE-2026-4447, describing it as a Chrome V8 Maglev Phi untagging vulnerability, but it does not provide PoC, exploit code, or mitigation details.

    113096426.0K
    93.0K followersView on X
  • xvonfers@xvonfers
    Patch

    (CVE-2026-4447)[486657483][maglev]Inappropriate implementation in V8. https://chromereleases.googleblog.com/2026/03/stable-channel-update-for-desktop_18.html Reported by Erge

    Post summary

    The snippet references CVE-2026-4447, mentions an inappropriate implementation in V8, and provides a link to a Chrome release page that implies a patch, but it lacks PoC, exploit, or detailed vulnerability data.

    100731.5K
    4.9K followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-4447 Inappropriate implementation in V8 in Google Chrome prior to 146.0.7680.153 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page… https://www.cve.org/CVERecord?id=CVE-2026-4447

    Post summary

    The text announces CVE‑2026‑4447, describing a V8 implementation flaw that enables remote code execution in Chrome via crafted HTML. No PoC, exploit, or patch details are provided.

    00000101
    56.8K followersView on X
CPE platform detail4 entries

4 of 4 entries

PartVendorProductVersionTarget SWTarget HW
OSapplemacos---
Appgooglechrome---
OSlinuxlinux_kernel---
OSmicrosoftwindows---

Explore more