Exploit discussion active in current signal (1 latest mentions)
Immediate actions
Patch apple chrome systems immediately
Hunt for exploitation attempts and persistence artifacts
Increase monitoring for publicly documented tradecraft
Recommended action window: High priority (within 72h)
NVD description
Out of bounds read and write in V8 in Google Chrome prior to 147.0.7727.55 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)
We picked Discord as the target, similar to our previous RCE (http://hacktron.ai/blog/discord-rce), it runs on chrome 138, nine versions behind.
Interestingly, the initial heap OOB was CVE-2026-5873, a turboshaft bounds-check bug. Patched in latest chrome. I think claude desktop, which uses chrome 146, is probably vulnerable.
Funnily enough, when I tested the OOB on my own chrome, it crashed. Turns out I didn't update to 147 chrome.
PoC below:
Post summary
The post details CVE‑2026‑5873 as a Chrome heap out‑of‑bounds bug that has been patched in recent releases, offers a PoC reference, yet provides no evidence of active exploitation or false claims.
Anthropic's Claude Opus with crafting a complete V8 exploit chain targeting an outdated Chrome 138 instance bundled in Discord, exploiting CVE-2026-5873 for remote code execution on macOS. After a week of guidance involving 2.3 billion tokens, over $2,200 in API costs, and roughly 20 hours of human intervention to navigate dead ends, the AI-generated code successfully achieved RCE by opening the macOS Calculator app.
The multi-phase exploit leveraged a Turboshaft WebAssembly out-of-bounds vulnerability, heap spraying, sandbox bypass techniques, and Wasm-specific primitives to escape Chrome's sandbox.
The experiment highlights how AI can accelerate n-day exploit development for unpatched Chromium-based apps, though it still required substantial human oversight.
Future models may eliminate the need for such hand-holding, potentially enabling faster attacks and urging quicker patching practices.
https://www.hacktron.ai/blog/i-let-claude-opus-to-write-me-a-chrome-exploit
Post summary
Anthropic’s Claude Opus was employed to go from a CVE description to working code that achieved RCE on macOS, showing how AI can accelerate n‑day exploit development, though human guidance was still necessary.
BREAKING: Researcher used Claude Opus to build full V8 exploit chain for CVE-2026-5873, popping outdated Chrome 138 in Discord after 2.3B tokens and $2,283 in API spend.
https://threatcluster.io/cluster/ai-model-exploits-outdated-chrome-version-in-security-test-dc49c775
Post summary
A researcher used Claude Opus to build a full V8 exploit chain for CVE‑2026‑5873, demonstrating the capability to target an outdated Chrome 138 in Discord, though no real‑world exploitation or patch information is disclosed.
$2,283 in API fees bought a working Chrome exploit via Claude Opus for CVE-2026-5873.
An out-of-bounds read/write in V8's Turboshaft WebAssembly compiler. Chrome 138 with V8 13.8.x. Reported March 25, 2026. Fixed in Chrome 147.0.7727.55.
The bug: i32.convert_i64 truncates a 64-bit index to 32 bits, then shifts left 2. After tier-up from Liftoff to Turboshaft, the bounds check is eliminated. Input 0x100000000n truncates to index 0, but the shifted access reaches 0x40000 bytes past the 64KB page - no trap.
The chain:
- ArrayBuffer spray for heap markers
- Wasm tier-up warmup
- Heap OOB to in-cage arbitrary R/W
- WasmCPT use-after-free via dispatch table corruption
- CanonicalSig type confusion, overwriting return (i64, ref $s) to (i64, i64) so struct pointers get read as raw i64
- SANDBOX_BASE derivation, sandbox escape
- WCPT redirect to system() for RCE
Demoed against Discord's bundled Chromium on ARM64 macOS, main window sandbox disabled. Popped Calculator.
One week. 1,765 API requests. 2.33 billion tokens. 20 hours of human supervision. 27 bug approaches before this one worked.
The model speculated offsets instead of verifying them, drifted in long sessions, and never self-recovered from a stuck state. Every dead end needed a human to re-scaffold.
First public exploit for this CVE.
https://www.hacktron.ai/blog/i-let-claude-opus-to-write-me-a-chrome-exploit
The grind of browser exploit dev has a receipt now.
Post summary
The text announces the creation of a fully functional Chrome exploit for CVE-2026-5873, detailing both the technical vulnerability and exploitation chain, and confirms that a patch has been released.