CVE-2026-85046
published 2026-09-03CVE-2026-85046: Type confusion in V8 in Google Chrome prior to 152.0.7977.82 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page…
PriorityP187high8.8CVSS 3.1
AVNACLPRNUIRSUCHIHAH
KEVITWEXPLOIT
CISA Known Exploited Vulnerabilitydue 2026-09-18
Exploited in the wild
EPSS
1.43%
71.4th percentile
Type confusion in V8 in Google Chrome prior to 152.0.7977.82 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: High)
Affected
4 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| chrome | < 152.0.7977.82 | 152.0.7977.82 | |
| chrome | >= 152.0.7977.82 < 152.0.7977.82 | 152.0.7977.82 | |
| chrome_desktop | — | — | |
| v8 | < 15.3.48 | 15.3.48 |
CVSS provenance
nvdv3.18.8HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
vulncheck8.8HIGH
cisa8.8HIGH
CVEs like this are exactly what “Exploited This Week” covers.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
CISA
Google Chromium V8 Type Confusion Vulnerability
cisa·2026-09-04·CVSS 8.8
CVE-2026-85046 [HIGH] CWE-843 Google Chromium V8 Type Confusion Vulnerability
Vulnerability: Google Chromium V8 Type Confusion Vulnerability
Affected: Google Chromium V8
Google Chromium V8 contains a type confusion vulnerability that allows a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. This vulnerability could affect multiple web browsers that utilize Chromium, including, but not limited to, Google Chrome, Microsoft Edge, and Opera.
Required Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are respon
Chrome
Stable Channel Update for Desktop: CVE-2026-85046
vendor_chrome·2026-09-03·CVSS 8.8
CVE-2026-85046 [HIGH] Stable Channel Update for Desktop: CVE-2026-85046
Stable Channel Update for Desktop
CVE-2026-85046: Type confusion in V8. Reported by Salvatore Gulizia (nickname: Serotav) on 2026-08-04 [N/A][ 502304489 ] High CVE-2026-85052: Out of bounds read in CrashReporting
Reported by Google on 2026-04-13 [N/A][ 533502257 ] High CVE-2026-85043: Incomplete cleanup in Network
Severity: high
VulDB
Google Chrome up to 152.0.7977.75 type confusion
vuldb·2026-09-03·CVSS 8.8
CVE-2026-85046 [HIGH] Google Chrome up to 152.0.7977.75 type confusion
A vulnerability has been found in Google Chrome and classified as critical. This impacts an unknown function. Performing a manipulation results in type confusion.
This vulnerability was named CVE-2026-85046. The attack may be initiated remotely. There is no available exploit.
The affected component should be upgraded.
GHSA
Type confusion in V8 in Google Chrome prior to 152.0.7977.82 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page.
ghsa_unreviewed·2026-09-03
CVE-2026-85046 [HIGH] CWE-843 Type confusion in V8 in Google Chrome prior to 152.0.7977.82 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page.
Type confusion in V8 in Google Chrome prior to 152.0.7977.82 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: High)
VulnCheck
Google Chromium V8 Type Confusion Vulnerability
vulncheck·2026·CVSS 8.8
CVE-2026-85046 [HIGH] CWE-843 Google Chromium V8 Type Confusion Vulnerability
Google Chromium V8 Type Confusion Vulnerability
Google Chromium V8 contains a type confusion vulnerability that allows a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. This vulnerability could affect multiple web browsers that utilize Chromium, including, but not limited to, Google Chrome, Microsoft Edge, and Opera.
Affected: Google Chromium V8
Required Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for eval
No detection rules found.
No public exploits indexed.
Hackernews
Four Spy Groups Used the Same Chrome and Windows Exploit Kit Within a Week
blogs_hackernews·2026-09-09·CVSS 8.8
CVE-2026-85046 [HIGH] Four Spy Groups Used the Same Chrome and Windows Exploit Kit Within a Week
Home
Threat Intelligence
Vulnerabilities
Cyber Attacks
Webinars
Expert Insights
Awards
Webinars
Awards
Free eBooks
About THN
Jobs
Advertise with us
## Four Spy Groups Used the Same Chrome and Windows Exploit Kit Within a Week
Multiple espionage-motivated threat activity clusters have been found deploying a previously undocumented exploit kit called BlueMoon that chains together multiple vulnerabilities in Microsoft Windows and Google Chrome.
The first in-the-wild use of BlueMoon has been attributed to the China-aligned state-sponsored group tracked as APT31 (aka Bronze Vinewood, Judgement Panda, JungleBamboo, PerplexedGoblin, RedBravo, TA412, Tide Castle, and Violet Typhoon) on August 28, 2026.
"Within days, several other espionage-motivated clusters began using BlueMoon,
Hackernews
Chrome V8 Zero-Day Exploited in the Wild Enables Code Execution Inside Sandbox
blogs_hackernews·2026-09-09·CVSS 8.8
CVE-2026-87491 [HIGH] Chrome V8 Zero-Day Exploited in the Wild Enables Code Execution Inside Sandbox
Home
Threat Intelligence
Vulnerabilities
Cyber Attacks
Webinars
Expert Insights
Awards
Webinars
Awards
Free eBooks
About THN
Jobs
Advertise with us
## Chrome V8 Zero-Day Exploited in the Wild Enables Code Execution Inside Sandbox
Google on Thursday released updates to patch 230 security vulnerabilities, including one that has come under active exploitation in the wild.
The medium-severity vulnerability, assigned the CVE identifier CVE-2026-87491 (CVSS score: N/A), has been described as an out-of-bounds bug in V8, Chrome's JavaScript and WebAssembly engine.
"Out-of-bounds write in V8 in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page," reads a description of the flaw on the NIST National Vu
Rapid7
Patch Tuesday - September 2026
blogs_rapid7·2026-09-08·CVSS 7.8
CVE-2026-85880 [HIGH] Patch Tuesday - September 2026
Microsoft is publishing 974 own-product vulnerabilities on September 2026 Patch Tuesday , including 723 vulnerabilities in Windows. Along with Microsoft fixes for 25 non-Microsoft CVEs, that brings the total number of vulnerabilities on the table today to 999. Whether this is the biggest Patch Tuesday ever depends on how we count, but this is by far the most CVEs that Microsoft has ever published in a single day. As Rapid7 noted last month, there is no reason to suppose that Patch Tuesday will ever return to the lower volumes we saw prior to 2026. Microsoft is aware of exploitation in the wild for two of the vulnerabilities published today.
## Windows ALPC: zero-day EoP
The eternal game of elevation of privilege whack-a-mole between Microsoft and attackers continues. This month, the batt
Hackernews
⚡ Weekly Recap: Chrome 0-Day, Router Hijacks, Coder Supply Chain Attack and More
blogs_hackernews·2026-09-07·CVSS 6.9
CVE-2026-86206 [MEDIUM] ⚡ Weekly Recap: Chrome 0-Day, Router Hijacks, Coder Supply Chain Attack and More
Home
Threat Intelligence
Vulnerabilities
Cyber Attacks
Webinars
Expert Insights
Awards
Webinars
Awards
Free eBooks
About THN
Jobs
Advertise with us
## ⚡ Weekly Recap: Chrome 0-Day, Router Hijacks, Coder Supply Chain Attack and More
Turning off email images should at least stop the pictures. This week, attackers had a workaround: a scannable QR code built out of text. It still appears, even with images blocked. A small detail, but an annoying one if that was a precaution you were counting on.
Elsewhere, a trusted software source delivered code that stole credentials, and a protocol designed for secure network management gave outsiders useful clues before login. Add active attacks on browsers, routers, and online stores, and there’s plenty to check—even for teams that have k
Hackernews
Google Releases Chrome Update to Patch Actively Exploited V8 Zero-Day
blogs_hackernews·2026-09-04·CVSS 8.8
CVE-2026-85046 [HIGH] Google Releases Chrome Update to Patch Actively Exploited V8 Zero-Day
Home
Threat Intelligence
Vulnerabilities
Cyber Attacks
Webinars
Expert Insights
Awards
Webinars
Awards
Free eBooks
About THN
Jobs
Advertise with us
## Google Releases Chrome Update to Patch Actively Exploited V8 Zero-Day
Google on Thursday released security updates to patch 12 vulnerabilities, including one that has come under active exploitation in the wild.
The high-severity vulnerability, tracked as CVE-2026-85046 (CVSS score: 8.8), has been described as a type confusion bug in V8, Chrome's JavaScript and WebAssembly engine.
"Type confusion in V8 in Google Chrome prior to 152.0.7977.82 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page," reads a description of the flaw in CVE.org.
Security researcher Salvatore Gulizia (aka S
https://chromereleases.googleblog.com/2026/09/stable-channel-update-for-desktop_01882797386.htmlhttps://issues.chromium.org/issues/542403045https://github.com/Serotav/Writeups/blob/77556c57999805fa7815a114da51d91cf24fbea9/v8/When_Sorting_Leads_To_Confusion.mdhttps://github.com/v8/v8/commit/e0562d87ad9c17042b581582c99237d798572e67https://news.ycombinator.com/item?id=49570669https://serotav.github.io/Writeups/v8/when-sorting-leads-to-confusion/https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-85046
2026-09-03
Published
2026-09-04
Added to CISA KEV
Exploited in the wild