PT-2026-31491 · Google+1 · Google Chrome+1

CVE-2026-5873

·

Published

2026-03-25

·

Updated

2026-08-31

CVSS v2.0

10

High

VectorAV:N/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Google Chrome versions prior to 147.0.7727.55
Description An out-of-bounds read and write issue exists in the V8 JavaScript engine, specifically within the Turboshaft WebAssembly compiler. The flaw occurs because the i32.convert i64 function truncates a 64-bit index to 32 bits before shifting it left by 2; during the tier-up process from Liftoff to Turboshaft, the bounds check is eliminated. This allows a remote attacker to execute arbitrary code inside a sandbox by enticing a user to visit a specially crafted HTML page. Real-world exploitation has been demonstrated on macOS ARM64 using a bundled Chromium instance in Discord to achieve remote code execution (RCE) by popping the Calculator application.
Recommendations Update Google Chrome to version 147.0.7727.55 or later.

Fix

DoS

RCE

Memory Corruption

Out of bounds Read

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2026-06290
CVE-2026-5873
OPENSUSE-SU-2026:10530-1
OPENSUSE-SU-2026:20575-1
OPENSUSE-SU-2026:20660-1

Affected Products

Google Chrome
Red Os