CVE-2026-85046

Published Sep 3, 2026

Last updated an hour ago

Overview

Description
Type confusion in V8 in Google Chrome prior to 152.0.7977.82 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: High)
Source
chrome-cve-admin@google.com
NVD status
Analyzed
Products
chrome

Risk scores

CVSS 3.1

Type
Secondary
Base score
8.8
Impact score
5.9
Exploitability score
2.8
Vector string
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Severity
HIGH

Known exploits

Data from CISA

Vulnerability name
Google Chromium V8 Type Confusion Vulnerability
Exploit added on
Sep 4, 2026
Exploit action due
Sep 18, 2026
Required action
Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.

Weaknesses

chrome-cve-admin@google.com
CWE-843

Social media

Hype score
Not currently trending
  1. 🔴 Chrome zero-day under active exploitation Google patched CVE-2026-85046, a V8 type confusion flaw already exploited in real-world attacks. It’s the 6th actively exploited Chrome zer https://t.co/3g11CyvLkJ #CVE #CVE202685046 #Chrome #GoogleChrome #ZeroDay #V8 #CyberSecu

    @stem__shop

    5 Sept 2026

    2 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  2. 🚨 Sandbox RCE in ALL Chromium browsers CVE-2026-85046: V8 type confusion, actively exploited. Google paid $1,000 for the report. Patch now → Chrome 152.0.7977.82 #Cybersecurity #Chrome #CVE #InfoSec https://t.co/dq23KXQIFD

    @VinodIgnites

    5 Sept 2026

    22 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  3. CISA 4 Sep: CVE-2026-85046 Chromium V8 type confusion added to KEV (active exploitation); FCEB due 18 Sep — catalog + alert. https://t.co/ARzS62lkOo

    @doomsignals

    5 Sept 2026

    6 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  4. 【朝のセキュリティ】脅威動向 (2026-09-05) 今日の焦点は2つ。Chromeのゼロデイ(CVE-2026-85046)が悪用確認済みでCISA KEV(KEV=悪用確認済み脆弱性の米国リスト)に登録。Citrix

    @toushikaka

    5 Sept 2026

    276 Impressions

    0 Retweets

    1 Like

    0 Bookmarks

    0 Replies

    0 Quotes

  5. 🔐 Daily Security & Standards Brief (Sep 04) CVE-2026-85046--Google Chromium V8 Type Confusion: patch Google Chromium V8 Type Confusion and verify the fix held. Full digest 👇 via PCMedicalist #CyberSecurity #InfoSec https://t.co/wG6B0po5a3

    @PCMedicalist

    5 Sept 2026

    24 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  6. Google Chromium V8 Type Confusion Vulnerability (CVE-2026-85046): Risk Analysis Google Chromium V8 type confusion vulnerability CVE-2026-85046 allows arbitrary code execution inside the browser sandbox via… Full write-up → link in bio #cybersecurity #infosec #cve #kev #goog

    @HotaSamit

    5 Sept 2026

    20 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  7. CVE-2026-85046 (Chrome V8 type confusion) is in CISA KEV, but EPSS is 0%. This isn't a free pass. Active exploitation confirms impact, but the low EPSS suggests a narrow attack surface or specific targeting. Don't just patch; understand your exposure.

    @BytesNora

    5 Sept 2026

    10 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  8. Attackers exploited CVE-2026-85046, a type confusion flaw in Chrome's V8 engine, through malicious JavaScript to achieve code execution within the browser sandbox. This marks the sixth Chrome zero-day patched in 2026, highlighting escalating browser-based attack campaigns.

    @aviatrixtrc

    5 Sept 2026

    37 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  9. Recent #Cybersecurity alerts: Google Chrome zero-day (CVE-2026-85046) actively exploited, compromising data in transit (Sept 4, 2026). MariaDB Connector/J (CVE-2026-55857) allows cleartext password transmission, impacting data privacy & integrity. Urgent patching needed. #New

    @YourAnon_irc

    4 Sept 2026

    35 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  10. 🚨 CRITICAL: CVE-2026-85046 - Google Chromium V8 type confusion vulnerability enables remote code execution via crafted HTML. Affects Chrome, Edge, Opera. CISA KEV listed. Patch immediately. #CVE #PatchNow #ThreatIntel https://t.co/GT5Dtp5XYT

    @DFIR_Lab

    4 Sept 2026

    32 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  11. 🔴 CISA Adds Google Chrome V8 Vulnerability to Exploited CVE Catalog CISA added CVE-2026-85046, a type confusion vulnerability in Google Chromium V8, to its Known Exploited Vulnerabilities (KEV) Catalog based on active exploitation evidence. Binding Operational Directive 26-04

    @NewsTongueX

    4 Sept 2026

    54 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  12. Chrome just patched its 6th actively-exploited zero-day of 2026. Restart your browser today — Positive explains why, Skeptic explains why you probably won't. Today's desk: Google fixed a high-severity Chrome V8 flaw (CVE-2026-85046) already being exploited in the wild; over ht

    @PositiveSkeptik

    4 Sept 2026

    62 Impressions

    1 Retweet

    1 Like

    1 Bookmark

    1 Reply

    0 Quotes

  13. Google Patches Exploited Chrome V8 Zero-Day CVE-2026-85046 Google has patched CVE-2026-85046, a high-severity V8 type confusion zero-day in Chrome exploited in the wild. Update to version… Full write-up → link in bio #cybersecurity #infosec #VulnerabilityDisclosure #google

    @HotaSamit

    4 Sept 2026

    47 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  14. 🐛 VULNERABILITIES Google patches actively exploited Chrome zero-day (CVE-2026-85046) — Help Net Security https://t.co/15n1s02GTn #Vulnerability #CVE #ZeroDay

    @MalwareObserver

    4 Sept 2026

    34 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  15. Google patches actively exploited Chrome zero-day (CVE-2026-85046) - https://t.co/tNfiguClv4 - #Chrome #ZeroDay #Vulnerability #CVE #exploit #Cybersecurity #CyberSecurityNews #SecurityNews

    @helpnetsecurity

    4 Sept 2026

    565 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  16. Google has patched 12 vulnerabilities affecting its popular Chrome browser, among them CVE-2026-85046, which has been exploited in the wild. “Google is aware that an exploit for CVE-2026-85046… https://t.co/d5tEGhXKlf #Google #Chrome #CyberSecurity #ZeroDay #Vulnerabilities

    @vtbcfeed

    4 Sept 2026

    36 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  17. Google patches actively exploited Chrome zero-day (CVE-2026-85046): Google has patched 12 vulnerabilities affecting its popular Chrome browser, among them CVE-2026-85046, which has been exploited in the wild. “Google is aware that an exploit for… https://t.co/Pzy8G1q6MG https

    @shah_sheikh

    4 Sept 2026

    48 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  18. 🐦 🚨 Chrome patched an actively exploited V8 0-day (CVE-2026-85046) — update now. JFrog Artifactory auth bypass (CVE-2026-82329, CVSS 9.8) is being exploited to forge admin tokens. SonicWall SMA1000 bugs (CVSS 10.0) just hit CISA's KEV list. #infosec #CVE #0day

    @ita_ipo

    4 Sept 2026

    87 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  19. Google Patches 6th Chrome Zero-Day of 2026 (CVE-2026-85046) - https://t.co/XSwQePtIm8

    @SecurityWeek

    4 Sept 2026

    1544 Impressions

    1 Retweet

    1 Like

    0 Bookmarks

    0 Replies

    0 Quotes

  20. 🛡️ CYBER BULLETIN | 2026/09/04 🚨 1. Chrome patches an actively exploited V8 zero-day Google shipped Chrome 152 to fix 12 bugs, including CVE-2026-85046, a type-confusion flaw in V8 already used in the wild. A crafted page can run code inside the sandbox. Update now — t

    @FrontieraTechIT

    4 Sept 2026

    55 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    1 Reply

    0 Quotes

  21. CHROME ALERT: Update Now! A new Chrome zero-day is being actively exploited. CVE-2026-85046 lets attackers run code on your machine via a malicious webpage. Read more: https://t.co/WNi4W3oqcq #Chrome #ZeroDay #CVE #V8 #SecurityUpdate #Google #InfoSec #TheHackerNews #PatchNow h

    @redsecuretech

    4 Sept 2026

    45 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  22. 🚨 [ACTIVE EXPLOITATION / BROWSER ZERO-DAY] — GOOGLE PATCHES A CHROME V8 FLAW ALREADY BEING EXPLOITED IN THE WILD A crafted HTML page can trigger arbitrary code execution inside Chrome’s sandbox. CyberSignal Priority: 🔴 VERY HIGH 🆔 CVE-2026-85046 ⚠️ CVSS: 8.8

    @XQOPTRX

    4 Sept 2026

    76 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  23. Chromeの更新は今日中に済ませたほうがいいです。 ・9月3日公開のv152.0.7977.82/.83でゼロデイCVE-2026-85046を修正 ・V8の型混乱で、Googleが悪用の確認を明記 ・9月1日にも26件を修正しており今週2回目 うちは更新の

    @coplusofficial

    4 Sept 2026

    9 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    1 Reply

    0 Quotes

  24. @Google ships Chrome 152.0.7977.83/82 fixing 12 vulnerabilities. High-severity V8 type confusion CVE-2026-85046 is already exploited in the wild after August disclosure. Additional fixes address race condition CVE-2026-85045 and use-after-free CVE-2026-85048 in Compositing.

    @WorldCyberNewsX

    4 Sept 2026

    46 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  25. Google patched a Chrome zero-day vulnerability currently exploited in the wild. The update resolves a severe V8 type confusion flaw (CVE-2026-85046). #Chrome #ZeroDay #Vulnerability #Cybersecurity #CVE202685046 https://t.co/HXymjvxwo8…

    @chris_uk2026

    4 Sept 2026

    6 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

Configurations