Skip to content
feed: live
>_0dayNews
CVE Record
[ HIGH ]CVE-2026-85046

Type confusion in Chrome V8 allows sandbox code execution

Type confusion in Chrome's V8 engine lets remote attackers run arbitrary code inside the browser sandbox via a crafted HTML page. Actively exploited; update to 152.0.7977.82.

cat cve-2026-85046.json
Vendor
Google
Product
Chrome (before 152.0.7977.82)
CVSS
8.8
EPSS (exploit probability)
N/A
Status
exploited-in-wild
Published

Type confusion in V8 in Google Chrome prior to 152.0.7977.82 allows a remote attacker to execute arbitrary code inside the browser sandbox through a crafted HTML page. Google confirmed active exploitation in the wild on September 4, 2026.

Security researcher Salvatore Gulizia (Serotav) reported the flaw on August 4, 2026. Google addressed it in Chrome 152.0.7977.82 for Linux and 152.0.7977.82/.83 for Windows and macOS.

Patch: Update Chrome to 152.0.7977.82 or later. Go to Help > About Google Chrome to trigger the update.