- Description
- Type confusion in V8 in Google Chrome prior to 152.0.7977.82 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: High)
- Source
- chrome-cve-admin@google.com
- NVD status
- Analyzed
- Products
- chrome
CVSS 3.1
- Type
- Secondary
- Base score
- 8.8
- Impact score
- 5.9
- Exploitability score
- 2.8
- Vector string
- CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
- Severity
- HIGH
Data from CISA
- Vulnerability name
- Google Chromium V8 Type Confusion Vulnerability
- Exploit added on
- Sep 4, 2026
- Exploit action due
- Sep 18, 2026
- Required action
- Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- chrome-cve-admin@google.com
- CWE-843
- Hype score
- Not currently trending
🔴 Chrome zero-day under active exploitation Google patched CVE-2026-85046, a V8 type confusion flaw already exploited in real-world attacks. It’s the 6th actively exploited Chrome zer https://t.co/3g11CyvLkJ #CVE #CVE202685046 #Chrome #GoogleChrome #ZeroDay #V8 #CyberSecu
@stem__shop
5 Sept 2026
2 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
🚨 Sandbox RCE in ALL Chromium browsers CVE-2026-85046: V8 type confusion, actively exploited. Google paid $1,000 for the report. Patch now → Chrome 152.0.7977.82 #Cybersecurity #Chrome #CVE #InfoSec https://t.co/dq23KXQIFD
@VinodIgnites
5 Sept 2026
22 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
CISA 4 Sep: CVE-2026-85046 Chromium V8 type confusion added to KEV (active exploitation); FCEB due 18 Sep — catalog + alert. https://t.co/ARzS62lkOo
@doomsignals
5 Sept 2026
6 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
【朝のセキュリティ】脅威動向 (2026-09-05) 今日の焦点は2つ。Chromeのゼロデイ(CVE-2026-85046)が悪用確認済みでCISA KEV(KEV=悪用確認済み脆弱性の米国リスト)に登録。Citrix
@toushikaka
5 Sept 2026
276 Impressions
0 Retweets
1 Like
0 Bookmarks
0 Replies
0 Quotes
🔐 Daily Security & Standards Brief (Sep 04) CVE-2026-85046--Google Chromium V8 Type Confusion: patch Google Chromium V8 Type Confusion and verify the fix held. Full digest 👇 via PCMedicalist #CyberSecurity #InfoSec https://t.co/wG6B0po5a3
@PCMedicalist
5 Sept 2026
24 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
Google Chromium V8 Type Confusion Vulnerability (CVE-2026-85046): Risk Analysis Google Chromium V8 type confusion vulnerability CVE-2026-85046 allows arbitrary code execution inside the browser sandbox via… Full write-up → link in bio #cybersecurity #infosec #cve #kev #goog
@HotaSamit
5 Sept 2026
20 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
CVE-2026-85046 (Chrome V8 type confusion) is in CISA KEV, but EPSS is 0%. This isn't a free pass. Active exploitation confirms impact, but the low EPSS suggests a narrow attack surface or specific targeting. Don't just patch; understand your exposure.
@BytesNora
5 Sept 2026
10 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
Attackers exploited CVE-2026-85046, a type confusion flaw in Chrome's V8 engine, through malicious JavaScript to achieve code execution within the browser sandbox. This marks the sixth Chrome zero-day patched in 2026, highlighting escalating browser-based attack campaigns.
@aviatrixtrc
5 Sept 2026
37 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
Recent #Cybersecurity alerts: Google Chrome zero-day (CVE-2026-85046) actively exploited, compromising data in transit (Sept 4, 2026). MariaDB Connector/J (CVE-2026-55857) allows cleartext password transmission, impacting data privacy & integrity. Urgent patching needed. #New
@YourAnon_irc
4 Sept 2026
35 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
🚨 CRITICAL: CVE-2026-85046 - Google Chromium V8 type confusion vulnerability enables remote code execution via crafted HTML. Affects Chrome, Edge, Opera. CISA KEV listed. Patch immediately. #CVE #PatchNow #ThreatIntel https://t.co/GT5Dtp5XYT
@DFIR_Lab
4 Sept 2026
32 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
🔴 CISA Adds Google Chrome V8 Vulnerability to Exploited CVE Catalog CISA added CVE-2026-85046, a type confusion vulnerability in Google Chromium V8, to its Known Exploited Vulnerabilities (KEV) Catalog based on active exploitation evidence. Binding Operational Directive 26-04
@NewsTongueX
4 Sept 2026
54 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
Chrome just patched its 6th actively-exploited zero-day of 2026. Restart your browser today — Positive explains why, Skeptic explains why you probably won't. Today's desk: Google fixed a high-severity Chrome V8 flaw (CVE-2026-85046) already being exploited in the wild; over ht
@PositiveSkeptik
4 Sept 2026
62 Impressions
1 Retweet
1 Like
1 Bookmark
1 Reply
0 Quotes
Google Patches Exploited Chrome V8 Zero-Day CVE-2026-85046 Google has patched CVE-2026-85046, a high-severity V8 type confusion zero-day in Chrome exploited in the wild. Update to version… Full write-up → link in bio #cybersecurity #infosec #VulnerabilityDisclosure #google
@HotaSamit
4 Sept 2026
47 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
🐛 VULNERABILITIES Google patches actively exploited Chrome zero-day (CVE-2026-85046) — Help Net Security https://t.co/15n1s02GTn #Vulnerability #CVE #ZeroDay
@MalwareObserver
4 Sept 2026
34 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
Google patches actively exploited Chrome zero-day (CVE-2026-85046) - https://t.co/tNfiguClv4 - #Chrome #ZeroDay #Vulnerability #CVE #exploit #Cybersecurity #CyberSecurityNews #SecurityNews
@helpnetsecurity
4 Sept 2026
565 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
Google has patched 12 vulnerabilities affecting its popular Chrome browser, among them CVE-2026-85046, which has been exploited in the wild. “Google is aware that an exploit for CVE-2026-85046… https://t.co/d5tEGhXKlf #Google #Chrome #CyberSecurity #ZeroDay #Vulnerabilities
@vtbcfeed
4 Sept 2026
36 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
Google patches actively exploited Chrome zero-day (CVE-2026-85046): Google has patched 12 vulnerabilities affecting its popular Chrome browser, among them CVE-2026-85046, which has been exploited in the wild. “Google is aware that an exploit for… https://t.co/Pzy8G1q6MG https
@shah_sheikh
4 Sept 2026
48 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
🐦 🚨 Chrome patched an actively exploited V8 0-day (CVE-2026-85046) — update now. JFrog Artifactory auth bypass (CVE-2026-82329, CVSS 9.8) is being exploited to forge admin tokens. SonicWall SMA1000 bugs (CVSS 10.0) just hit CISA's KEV list. #infosec #CVE #0day
@ita_ipo
4 Sept 2026
87 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
Google Patches 6th Chrome Zero-Day of 2026 (CVE-2026-85046) - https://t.co/XSwQePtIm8
@SecurityWeek
4 Sept 2026
1544 Impressions
1 Retweet
1 Like
0 Bookmarks
0 Replies
0 Quotes
🛡️ CYBER BULLETIN | 2026/09/04 🚨 1. Chrome patches an actively exploited V8 zero-day Google shipped Chrome 152 to fix 12 bugs, including CVE-2026-85046, a type-confusion flaw in V8 already used in the wild. A crafted page can run code inside the sandbox. Update now — t
@FrontieraTechIT
4 Sept 2026
55 Impressions
0 Retweets
0 Likes
0 Bookmarks
1 Reply
0 Quotes
CHROME ALERT: Update Now! A new Chrome zero-day is being actively exploited. CVE-2026-85046 lets attackers run code on your machine via a malicious webpage. Read more: https://t.co/WNi4W3oqcq #Chrome #ZeroDay #CVE #V8 #SecurityUpdate #Google #InfoSec #TheHackerNews #PatchNow h
@redsecuretech
4 Sept 2026
45 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
🚨 [ACTIVE EXPLOITATION / BROWSER ZERO-DAY] — GOOGLE PATCHES A CHROME V8 FLAW ALREADY BEING EXPLOITED IN THE WILD A crafted HTML page can trigger arbitrary code execution inside Chrome’s sandbox. CyberSignal Priority: 🔴 VERY HIGH 🆔 CVE-2026-85046 ⚠️ CVSS: 8.8
@XQOPTRX
4 Sept 2026
76 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
Chromeの更新は今日中に済ませたほうがいいです。 ・9月3日公開のv152.0.7977.82/.83でゼロデイCVE-2026-85046を修正 ・V8の型混乱で、Googleが悪用の確認を明記 ・9月1日にも26件を修正しており今週2回目 うちは更新の
@coplusofficial
4 Sept 2026
9 Impressions
0 Retweets
0 Likes
0 Bookmarks
1 Reply
0 Quotes
@Google ships Chrome 152.0.7977.83/82 fixing 12 vulnerabilities. High-severity V8 type confusion CVE-2026-85046 is already exploited in the wild after August disclosure. Additional fixes address race condition CVE-2026-85045 and use-after-free CVE-2026-85048 in Compositing.
@WorldCyberNewsX
4 Sept 2026
46 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
Google patched a Chrome zero-day vulnerability currently exploited in the wild. The update resolves a severe V8 type confusion flaw (CVE-2026-85046). #Chrome #ZeroDay #Vulnerability #Cybersecurity #CVE202685046 https://t.co/HXymjvxwo8…
@chris_uk2026
4 Sept 2026
6 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
[
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:a:google:chrome:*:*:*:*:*:*:*:*",
"matchCriteriaId": "E7133861-8AAD-49BB-9137-9D737B466E1E",
"versionEndExcluding": "152.0.7977.82",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
]