CVE-2026-5873Exploit(apple / chrome)

MEDIUMCVSS 8.8 · HIGH

Exploit discussion active in current signal (1 latest mentions)

Immediate actions

  • Patch apple chrome systems immediately
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft

Recommended action window: High priority (within 72h)

NVD description

Out of bounds read and write in V8 in Google Chrome prior to 147.0.7727.55 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)

5.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-125CWE-787

Priority

MEDIUM

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • chrome
  • linux_kernel
  • macos
  • windows

Threat summary

  • Public PoC and exploit tooling are both present
  • Patch or workaround signal is available
  • 4 mentions across 3 observed days
  • Momentum state: stable

What's happening

  • Exploit tool or code specified in 2 signals
  • PoC mentioned or linked in 4 signals
  • Patch or workaround mentioned in 2 signals
  • Technical details provided in 4 signals
  • Peaked 1d ago at 2 mentions (2026-04-16); latest day: 1
  • 4 total mentions across 3 days

Affected systems

Products
chromelinux_kernelmacoswindows

1 version affected across 4 products

Deep dive

Activity timeline4 mentions / 3d
01122Mentions · 2026-04-15: 1Mentions · 2026-04-16: 2Mentions · 2026-04-17: 1PoC Mentioned / Linked · 2026-04-15: 1PoC Mentioned / Linked · 2026-04-16: 2PoC Mentioned / Linked · 2026-04-17: 1Exploit Tool / Code · 2026-04-16: 1Exploit Tool / Code · 2026-04-17: 1Patch / Workaround · 2026-04-15: 1Patch / Workaround · 2026-04-16: 1Technical Details · 2026-04-15: 1Technical Details · 2026-04-16: 2Technical Details · 2026-04-17: 104-1504-1604-17
Signal classification2 categories
Exploit
375.0%
PoC
125.0%
Referenced assets3 URLs
Classification over time
DateTotalLabels
2026-04-151
PoC1
2026-04-162
Exploit2
2026-04-171
Exploit1
Full discourse4 posts
  • s1r1us (mohan)@S1r1u5_
    PoC

    We picked Discord as the target, similar to our previous RCE (http://hacktron.ai/blog/discord-rce), it runs on chrome 138, nine versions behind. Interestingly, the initial heap OOB was CVE-2026-5873, a turboshaft bounds-check bug. Patched in latest chrome. I think claude desktop, which uses chrome 146, is probably vulnerable. Funnily enough, when I tested the OOB on my own chrome, it crashed. Turns out I didn't update to 147 chrome. PoC below:

    Post summary

    The post details CVE‑2026‑5873 as a Chrome heap out‑of‑bounds bug that has been patched in recent releases, offers a PoC reference, yet provides no evidence of active exploitation or false claims.

    121722216.8K
    13.6K followersView on X
  • heretic-x@ggmania
    Exploit

    Anthropic's Claude Opus with crafting a complete V8 exploit chain targeting an outdated Chrome 138 instance bundled in Discord, exploiting CVE-2026-5873 for remote code execution on macOS. After a week of guidance involving 2.3 billion tokens, over $2,200 in API costs, and roughly 20 hours of human intervention to navigate dead ends, the AI-generated code successfully achieved RCE by opening the macOS Calculator app. The multi-phase exploit leveraged a Turboshaft WebAssembly out-of-bounds vulnerability, heap spraying, sandbox bypass techniques, and Wasm-specific primitives to escape Chrome's sandbox. The experiment highlights how AI can accelerate n-day exploit development for unpatched Chromium-based apps, though it still required substantial human oversight. Future models may eliminate the need for such hand-holding, potentially enabling faster attacks and urging quicker patching practices. https://www.hacktron.ai/blog/i-let-claude-opus-to-write-me-a-chrome-exploit

    Post summary

    Anthropic’s Claude Opus was employed to go from a CVE description to working code that achieved RCE on macOS, showing how AI can accelerate n‑day exploit development, though human guidance was still necessary.

    00010115
    431 followersView on X
  • ThreatCluster@threatcluster
    Exploit

    BREAKING: Researcher used Claude Opus to build full V8 exploit chain for CVE-2026-5873, popping outdated Chrome 138 in Discord after 2.3B tokens and $2,283 in API spend. https://threatcluster.io/cluster/ai-model-exploits-outdated-chrome-version-in-security-test-dc49c775

    Post summary

    A researcher used Claude Opus to build a full V8 exploit chain for CVE‑2026‑5873, demonstrating the capability to target an outdated Chrome 138 in Discord, though no real‑world exploitation or patch information is disclosed.

    00000159
    155 followersView on X
  • SecureChap@SecureChap
    Exploit

    $2,283 in API fees bought a working Chrome exploit via Claude Opus for CVE-2026-5873. An out-of-bounds read/write in V8's Turboshaft WebAssembly compiler. Chrome 138 with V8 13.8.x. Reported March 25, 2026. Fixed in Chrome 147.0.7727.55. The bug: i32.convert_i64 truncates a 64-bit index to 32 bits, then shifts left 2. After tier-up from Liftoff to Turboshaft, the bounds check is eliminated. Input 0x100000000n truncates to index 0, but the shifted access reaches 0x40000 bytes past the 64KB page - no trap. The chain: - ArrayBuffer spray for heap markers - Wasm tier-up warmup - Heap OOB to in-cage arbitrary R/W - WasmCPT use-after-free via dispatch table corruption - CanonicalSig type confusion, overwriting return (i64, ref $s) to (i64, i64) so struct pointers get read as raw i64 - SANDBOX_BASE derivation, sandbox escape - WCPT redirect to system() for RCE Demoed against Discord's bundled Chromium on ARM64 macOS, main window sandbox disabled. Popped Calculator. One week. 1,765 API requests. 2.33 billion tokens. 20 hours of human supervision. 27 bug approaches before this one worked. The model speculated offsets instead of verifying them, drifted in long sessions, and never self-recovered from a stuck state. Every dead end needed a human to re-scaffold. First public exploit for this CVE. https://www.hacktron.ai/blog/i-let-claude-opus-to-write-me-a-chrome-exploit The grind of browser exploit dev has a receipt now.

    Post summary

    The text announces the creation of a fully functional Chrome exploit for CVE-2026-5873, detailing both the technical vulnerability and exploitation chain, and confirms that a patch has been released.

    0000067
    6 followersView on X
CPE platform detail4 entries

4 of 4 entries

PartVendorProductVersionTarget SWTarget HW
OSapplemacos---
Appgooglechrome---
OSlinuxlinux_kernel---
OSmicrosoftwindows---

Explore more