CVE-2026-5865General(apple / chrome)

MEDIUMCVSS 8.8 · HIGH

Exploit discussion active in current signal (1 latest mentions)

Immediate actions

  • Patch apple chrome systems immediately
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft

Recommended action window: High priority (within 72h)

NVD description

Type Confusion in V8 in Google Chrome prior to 147.0.7727.55 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)

5.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-843

Priority

MEDIUM

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • chrome
  • linux_kernel
  • macos
  • windows

Threat summary

  • Public PoC and exploit tooling are both present
  • Patch or workaround signal is available
  • 9 mentions across 7 observed days
  • Momentum state: stable

What's happening

  • Exploit tool or code specified in 1 signal
  • PoC mentioned or linked in 4 signals
  • Patch or workaround mentioned in 2 signals
  • Technical details provided in 6 signals
  • General: 4 classified signals
  • Disclosure: 2 classified signals
  • Peaked 3d ago at 3 mentions (2026-05-07); latest day: 1
  • 9 total mentions across 7 days

Affected systems

Products
chromelinux_kernelmacoswindows

1 version affected across 4 products

Deep dive

Activity timeline9 mentions / 7d
01223Mentions · 2026-04-23: 1Mentions · 2026-05-05: 1Mentions · 2026-05-06: 1Mentions · 2026-05-07: 3Mentions · 2026-05-09: 1Mentions · 2026-06-05: 1Mentions · 2026-06-15: 1PoC Mentioned / Linked · 2026-05-06: 1PoC Mentioned / Linked · 2026-05-07: 1PoC Mentioned / Linked · 2026-05-09: 1PoC Mentioned / Linked · 2026-06-15: 1Exploit Tool / Code · 2026-06-15: 1Patch / Workaround · 2026-04-23: 1Patch / Workaround · 2026-06-15: 1Technical Details · 2026-04-23: 1Technical Details · 2026-05-06: 1Technical Details · 2026-05-07: 1Technical Details · 2026-05-09: 1Technical Details · 2026-06-05: 1Technical Details · 2026-06-15: 104-2305-0505-0605-0705-0906-0506-15
Signal classification3 categories
General
444.4%
PoC
333.3%
Disclosure
222.2%
Referenced assets10 URLs
Classification over time
DateTotalLabels
2026-04-231
Disclosure1
2026-05-051
General1
2026-05-061
PoC1
2026-05-073
General2PoC1
2026-05-091
Disclosure1
2026-06-051
General1
2026-06-151
PoC1
Full discourse9 posts
  • Nebula Security@nebusecurity
    PoC

    Tomorrow, we’re releasing the full technical walkthrough for CVE-2026-5865, a chrome v8 0-day found by our AI security agent "Vega". More Linux kernel and Chrome 0-day writeups are coming later this month. Stay tuned, and follow our bug list for updates: https://nebusec.ai/buglist/ https://t.co/LtVm6sfkcN

    Post summary

    The post announces an upcoming full technical walkthrough for CVE‑2026‑5865, a Chrome V8 zero‑day, but does not yet provide exploit code or evidence of active attacks.

    10965572318102.3K
    5.5K followersView on X
  • NebuSec@nebusecurity
    Disclosure

    Meet CVE-2026-5865: the first Chrome V8 zero-day our AI security agent discovered back in March. It led to renderer memory read/write and potential RCE, affected 40+ major Chrome versions, and has now been patched following our report to Google. In line with our disclosure policy, we’ll publish the full technical write-up on May 7th (30 days after the fixes rolled out). Stay tuned.

    Post summary

    The post announces that CVE-2026-5865, a Chrome V8 zero‑day affecting over 40 major Chrome versions, was discovered by an AI agent and has since been patched by Google; a full technical write‑up is slated for release 30 days later.

    661248020145.1K
    5.5K followersView on X
  • Nebula Security@nebusecurity
    PoC

    One omitted write barrier can turn into RCE in Chrome. Meet CVE-2026-5865, one of the earliest Chrome vulnerabilities discovered by Vega in March. We turned it into an RCE in Chrome, documented the details in our technical walkthrough, link in the comment. https://t.co/ENeroVV437

    Post summary

    The post announces CVE‑2026‑5865, explains how an omitted write barrier leads to an RCE in Chrome, and shares a link to a technical walkthrough of the exploit.

    223216110120.9K
    5.5K followersView on X
  • Chromia | Power to the Public@Chromia
    General

    CVE-2026-5865. Another agent vulnerability, no patch timeline. Pattern's repeat faster than fixes are shipped. Centralised logs can be edited. That's not an audit trail, that's a liability. On-chain = immutable, timestamped, verifiable by anyone. If your agent can't prove what it did, you don't have governance. You have hope. Source: https://x.com/nebusecurity/status/2047153356536250770

    Post summary

    The tweet identifies CVE‑2026‑5865 as an agent vulnerability with no patch timeline and offers no technical or remediation details.

    4713722.1K
    159.3K followersView on X
  • dbugs@ptdbugs
    PoC

    CVE: CVE-2026-5865 PT ID: PT-2026-31483 Vendor: Google Product: Chrome CVSS: 8.8 Credits: n/a Description: Type Confusion in V8 in Google Chrome prior to 147.0.7727.55 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High) References: • https://dbugs.ptsecurity.com/vulnerability/CVE-2026-5865 • https://chromereleases.googleblog.com/2026/04/stable-channel-update-for-desktop.html • https://issues.chromium.org/issues/491884710 PoC/Exploit: https://github.com/Crihexe/v8-poc-CVE-2026-5865 #dbugs_vuln

    Post summary

    The text announces a type confusion vulnerability in Chrome and provides a PoC/exploit code; it references a patch release but does not indicate active exploitation.

    00021267
    3.0K followersView on X
  • Agent X AGI@agentxagi
    General

    @lyq_sqsp the agent wasn't smarter — it was unbiased. humans saw patched and stopped looking. the agent evaluated fresh every time. 3rd case in our data: Claude Mythos found 271 Firefox vulns, CVE-2026-5865 agent found V8 zero-day. agents don't carry we-fixed-that bias.

    Post summary

    An agent is reported to have found 271 Firefox flaws and a V8 zero‑day (CVE‑2026‑5865), but no PoC, exploit code, active exploitation claims, or patch information are provided.

    00020174
    397 followersView on X
  • CVETrends@CVEShield
    General

    Top 5 Trending CVEs: 1 - CVE-2026-31431 2 - CVE-2026-5865 3 - CVE-2026-0300 4 - CVE-2026-3854 5 - CVE-2026-22679 #cve #cvetrends #cveshield #cybersecurity https://www.cveshield.com/dashboard

    Post summary

    The post merely lists five trending CVEs without providing context, technical details, or actionable information.

    00011215
    1.7K followersView on X
  • VulnTracker@vuln_tracker
    General

    @nebusecurity Genuinely excited to read the Vega writeup tomorrow. AI-assisted vuln discovery at this level is a signal of where offensive research is heading. For defenders tracking Chrome 0-day exposure - we've got CVE-2026-5865 live in the feed. http://vulntracker.io

    Post summary

    The message simply announces that CVE‑2026‑5865 is now live in a vulnerability feed, providing no details on PoC, exploitation status, or remediation.

    000111.0K
    619 followersView on X
  • N45HT@N45HTOfficial
    Disclosure

    How an Omitted Write Barrier in V8 Turns Into RCE in Chrome: CVE-2026-5865 👾💥 👨‍💻 Vega AI (Nebula Security) 🔗 https://nebusec.ai/research/v8-maglev-incorrect-phis-untagging/?a=6 🔗 https://nvd.nist.gov/vuln/detail/CVE-2026-5865 https://t.co/KaQEOTTTdZ

    Post summary

    The post announces a new V8 engine vulnerability (CVE‑2026‑5865) that enables remote code execution in Chrome, linking to research that likely includes a PoC, but no exploit code or active exploitation evidence is provided.

    00000108
    86 followersView on X
CPE platform detail4 entries

4 of 4 entries

PartVendorProductVersionTarget SWTarget HW
OSapplemacos---
Appgooglechrome---
OSlinuxlinux_kernel---
OSmicrosoftwindows---

Explore more