LiveBreach Intelligence: data breaches, leaks & ransomware, tracked as they surfaceOngoing protection: GalaxyWarden →
Recent BreachesData breach tracker

CVE-2026-85046: Google Chromium V8 Type Confusion Vulnerability

RBRecent Breaches Vulnerability Intelligence·Sep 4, 2026
CVSS 8.8 · High⚠ Actively exploited (CISA KEV)
8.8
CVSS score
High
Severity
Active
CISA KEV
No
Ransomware use
Sep 18, 2026
Patch deadline
⚠ Exploited in the wild. CISA added CVE-2026-85046 to its Known Exploited Vulnerabilities catalog on Sep 4, 2026, with a federal patch deadline of Sep 18, 2026 — meaning attackers are actively using it. If you run the affected software, patch it immediately.

Type confusion in V8 in Google Chrome prior to 152.0.7977.82 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: High)

CVE-2026-85046 is a type confusion flaw in Google Chromium’s V8 JavaScript engine. A remote attacker can use a crafted HTML page to run arbitrary code inside the browser sandbox. Because many browsers embed Chromium, the issue can affect Google Chrome, Microsoft Edge, Opera, and other Chromium-based products. Confirm exact product coverage and fixed builds against the vendor advisory.

For IT and security teams, this matters because drive-by web content is a common initial access path. Successful abuse can lead to code execution in the renderer/sandbox context and, depending on other flaws or misconfiguration, further impact on the endpoint. Known ransomware use is not documented for this CVE.

How it works

The weakness is classified as CWE-843 (type confusion). In engines like V8, objects are expected to match specific internal types. When code confuses one type for another, memory is interpreted incorrectly. An attacker who can supply malicious JavaScript or HTML can trigger that mismatch.

Per the CISA summary, the result is arbitrary code execution inside the sandbox via a crafted HTML page. That typically means the victim only needs to load attacker-controlled web content in a vulnerable Chromium-based browser. Public detail beyond that class of abuse is limited; do not assume specific exploit chains, privilege escalation out of the sandbox, or reliability without vendor and independent analysis. Treat any “proof of concept” claims as untrusted until verified against official guidance.

Am I affected? How to find it in your systems

Chromium V8 ships inside desktop and some managed browser installs, kiosk/VDI images, developer workstations, and applications that embed a Chromium runtime. Inventory should cover more than “Chrome only.”

How to remediate

Patch first. Apply the vendor security update that addresses CVE-2026-85046 for each Chromium-based product you run, following the browser vendor’s instructions. CISA’s required action is to apply mitigations per vendor instructions, align with BOD 26-04 prioritization of security updates based on risk, and follow CISA forensics triage requirements where applicable. For cloud-delivered or managed browser services, follow applicable BOD 26-04 guidance; if mitigations are unavailable, discontinue use of the product as directed by that guidance.

If you can't patch immediately

Reduce exposure until updates are installed everywhere.

If your data may have been exposed

Actively exploited browser vulnerabilities are a frequent path into endpoints and, from there, into accounts and data. If you suspect compromise—suspicious browser behavior, credential theft alerts, or confirmed intrusion—follow your incident response process, preserve evidence per CISA forensics triage expectations, rotate credentials from trusted devices, and review access logs. Known ransomware use is not documented for this CVE; still treat successful code execution as a serious incident. You can run a free exposure scan of your email to check known breach data and prioritize password and session resets where your addresses appear.

AICompiled with AI assistance from public sources and published under our editorial standards.

Details

AffectedGoogle · Chromium V8
WeaknessCWE-843
CVSS base score8.8 (High)
CVSS vectorCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
PublishedSep 3, 2026
Added to CISA KEVSep 4, 2026
Federal patch deadlineSep 18, 2026
Known ransomware useNot documented
Check if your data is exposed →

References

Official records: NVD · CISA KEV

← All actively-exploited vulnerabilities