← back

CVE-2026-85046

HIGH · 8.8 KEV EPSS 1.3%
hype ACTIVE HACK · 89 hack

KEV-listed, vendor patched emergently, active exploitation confirmed, mass update required

What: Type confusion in V8 JavaScript engine in Google Chrome prior to v152.0.7977.82 allows remote arbitrary code execution within the sandbox via crafted HTML. CVSS 8.8 (HIGH).

Why it matters: KEV-listed as of 2026-09-04; Google issued urgent patch within 24 hours of CVE publication. Social chatter consistently reports active exploitation in the wild across all Chromium versions. High-severity sandbox escape affecting billions of users demands immediate patching.

Where it's seen: Bluesky and Hacker News amplifying patch advisory and KEV status. Repetitive posts emphasize "actively exploited" and link to NVD/vendor guidance. No public PoC code shared yet, but urgency signals vendor awareness of ongoing abuse.

RISK: CRITICAL — Sandbox RCE, KEV-listed, actively exploited, billions of Chrome users affected

Generated by claude-haiku-4-5 from public posts and authoritative metadata. AI can make mistakes — verify against vendor advisories before acting. 9/5/2026, 3:43:08 AM

Description

Type confusion in V8 in Google Chrome prior to 152.0.7977.82 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: High)

CVSS 3.1 breakdown

Exploitability 2.8 · Impact 5.9
vector CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Attack vector
Network
Complexity
Low
Privileges required
None
User interaction
Required
Scope
Unchanged
Confidentiality
High
Integrity
High
Availability
High

Weaknesses