EIP-2026-115648

PRE-CVE

Microsoft Edge Chakra - OP_Memset Type Confusion

Title source: legacy
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for EIP-2026-115648. PoCs published by Google Security Research.

AI-analyzed exploit summary This exploit leverages a type confusion vulnerability in JavaScript engines by manipulating the OP_Memset operation to bypass input validation, similar to CVE-2018-8372. It uses Proxy and array manipulations to trigger the vulnerability, potentially leading to arbitrary memory manipulation.

Description

Microsoft Edge Chakra - OP_Memset Type Confusion

Exploits (1)

exploitdb WORKING POC VERIFIED
by Google Security Research · javascriptdoswindows
https://www.exploit-db.com/exploits/45889

This exploit leverages a type confusion vulnerability in JavaScript engines by manipulating the OP_Memset operation to bypass input validation, similar to CVE-2018-8372. It uses Proxy and array manipulations to trigger the vulnerability, potentially leading to arbitrary memory manipulation.

Classification
Working Poc 90%
Attack Type
Rce
Complexity
Complex
Reliability
Theoretical
Target: JavaScript engines (likely targeting a specific browser or runtime, e.g., V8 or ChakraCore)
No auth needed
Prerequisites: Victim must execute the JavaScript code in a vulnerable environment
devstral-2 · analyzed Feb 16, 2026 Full analysis →

Details

Status pre_cve
Tracked Since Feb 18, 2026