HIGHZero Day
Verified
Global
Chrome Zero-Day Exploited by Spyware Vendor Against Journalists
Monday, March 23, 2026 at 08:00 PM UTC·Source: Google Threat Analysis Group
Updated: Tuesday, March 24, 2026 at 10:00 AM UTC
Executive Summary
Google patches V8 zero-day exploited by commercial spyware vendor. One-click full chain achieves RCE targeting journalists and activists.
Analysis
CVE-2026-1893 is a V8 type confusion enabling full sandbox escape via single malicious link. Google TAG identified a European spyware vendor targeting journalists, activists, and opposition politicians. Payload includes device monitoring, encrypted message interception, mic/camera activation.
Timeline
Discovered
Mar 19, 2026
Exploitation Detected
Mar 19, 2026
Published
Mar 23, 2026
Patch Available
Mar 23, 2026