← Vulnerability feed

Vulnerability record · CVE-2026-85046 · published 3 September 2026

CVE-2026-85046: Google Chrome V8 type confusion enables sandboxed remote code execution

Google · Chrome

Chrome's V8 JavaScript engine contains a type confusion flaw (CWE-843) fixed in version 152.0.7977.82. A crafted HTML page can trigger the confusion and lead to arbitrary code execution inside the browser sandbox. The issue is rated High by Chromium and carries a CVSS 3.1 base score of 8.8, and it has been added to CISA's Known Exploited Vulnerabilities catalog.

8.8 CVSS 3.1 High CISA KEV since 4 Sep 2026 EPSS 49% · top 1.2% CWE-843 · Type confusion
8.8CVSS 3.1 base score
49%EPSS exploitation probability, 30 days
YesIn CISA KEV, fix deadline passed
2Affected product versions listed by NVD
7References, 2 tagged exploit
21 Sep 2026Last modified by NVD

Description

Type confusion in V8 in Google Chrome prior to 152.0.7977.82 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: High)

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 17 September 2026. Confidence: high.

high priorityCVSS 8.8 with remote code execution in a ubiquitous browser and confirmed inclusion in CISA KEV outweigh the moderate EPSS score.

What it is

Chrome's V8 JavaScript engine contains a type confusion flaw (CWE-843) fixed in version 152.0.7977.82. A crafted HTML page can trigger the confusion and lead to arbitrary code execution inside the browser sandbox. The issue is rated High by Chromium and carries a CVSS 3.1 base score of 8.8, and it has been added to CISA's Known Exploited Vulnerabilities catalog.

Impact

An attacker who gets the page rendered can execute arbitrary code within the Chrome sandbox, giving control of the renderer process and a foothold for sandbox escape or further compromise. Confidentiality, integrity and availability impacts are all rated High.

Attack surface

Reached over the network through a crafted HTML page rendered in Chrome; no privileges are required but user interaction (opening or visiting the page) is needed per the CVSS vector AV:N/AC:L/PR:N/UI:R. The flaw lives in V8, so any context that executes attacker-supplied JavaScript is a potential vector.

Exploitation

CVE-2026-85046 is listed in CISA KEV with a remediation due date of 2026-09-18, and public references are tagged as Exploit, indicating known exploitation. EPSS is modest (0.01462, ~72nd percentile), so the KEV listing is the stronger signal. No ransomware campaign use is documented.

What to do

  • Update Chrome to 152.0.7977.82 or later on all platforms and confirm the version in chrome://version.
  • Apply the referenced V8 patch (commit e0562d87ad9c17042b581582c99237d798572e67) if you build Chromium or V8 from source.
  • Prioritize internet-facing and unmanaged endpoints for patching within the CISA KEV due date of 2026-09-18.
  • If immediate patching is not possible, restrict browsing to trusted sites and enforce site isolation and other renderer hardening controls.
  • Track the Chromium issue 542403045 and vendor release notes for any follow-up fixes.

Detection

  • Monitor for Chrome renderer crashes or abnormal process terminations that cluster around browsing of untrusted pages.
  • Hunt for chrome.exe or chrome child processes spawning unexpected executables or making anomalous outbound connections.
  • Alert on Chrome versions below 152.0.7977.82 across managed endpoints via software inventory.
  • Review proxy and DNS logs for access to known exploit-hosting or writeup-linked domains around the time of suspected incidents.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Exploitation in the wild

CISA added CVE-2026-85046 to the Known Exploited Vulnerabilities catalog on 4 September 2026 as "Google Chromium V8 Type Confusion Vulnerability". Required action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines. Federal deadline 18 September 2026.

Affected products

2 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2026-85046 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2025-10585Google Chrome V8 type confusion enables heap corruptionChrome's V8 JavaScript engine contains a type confusion flaw (CWE-843) that can lead to heap corruption when processing a crafted HTML page. It affec…KEVEPSS 5.4%analysed9.8CVE-2014-0497Adobe Flash Player integer underflow allows remote code executionAdobe Flash Player contains an integer underflow (CWE-191) that allows remote attackers to execute arbitrary code via unspecified vectors. The flaw a…KEVEPSS 100%analysed9.6CVE-2024-7971Google Chrome V8 type confusion enables heap corruptionChrome's V8 JavaScript engine contains a type confusion flaw (CWE-843) that lets a crafted HTML page corrupt the heap. It affects Chrome before 128.0…KEVEPSS 21%analysed9.6CVE-2024-5274Google Chrome V8 type confusion allows sandbox code executionGoogle Chrome before 125.0.6422.112 contains a type confusion flaw in the V8 JavaScript engine. A crafted HTML page can trigger the confusion and lea…KEVEPSS 7.5%analysed9.6CVE-2024-4947Google Chrome V8 type confusion allows sandboxed remote code executionGoogle Chrome before 125.0.6422.60 contains a type confusion flaw in the V8 JavaScript engine. A crafted HTML page can trigger the confusion and let …KEVEPSS 15%analysed9.6CVE-2024-4671Google Chrome Visuals use-after-free enables sandbox escapeCVE-2024-4671 is a use-after-free flaw in the Visuals component of Google Chrome prior to 124.0.6367.201. An attacker who has already compromised the…KEVEPSS 8.3%analysed9.6CVE-2023-6345Chrome Skia integer overflow enables sandbox escapeAn integer overflow in Skia in Google Chrome before 119.0.6045.199 lets a remote attacker who already controls the renderer process escape the browse…KEVEPSS 16%analysed9.6CVE-2023-2136Google Chrome Skia integer overflow enables sandbox escapeAn integer overflow in the Skia graphics library in Google Chrome before 112.0.5615.137 lets an attacker who already controls the renderer process es…KEVEPSS 5.7%analysed

Source: NIST National Vulnerability Database (record CVE-2026-85046), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.