CTIPilot

Google Chrome Compositing use-after-free, High severity, no reported exploitation

cve · CVE-2026-85048 single-source

Coverage timeline
1
first 2026-09-04 → last 2026-09-04
Peak priority
high
1 high
Sources cited
3
3 hosts
Sections touched
1
trending-vulnerabilities
Co-occurring entities
8
see Co-occurring entities below
ATT&CK techniques
2
pinned v19.2 · see below

ATT&CK techniques

2 techniques observed across 1 entry, derived from entry metadata and body evidence, never asserted without a published entry behind it · pinned to MITRE ATT&CK v19.2 · compare on the matrix · Navigator layer (JSON)

Initial Access TA0001

T1189Drive-by Compromise×1

Adversaries may gain access to a system through a user visiting a website over the normal course of browsing. Multiple ways of delivering exploit code to a browser exist (i.e., Drive-by Target), including:

Evidence: 2026-09-04/cve-2026-85046-chrome-v8-type-confusion-exploited · ATT&CK page ↗

Execution TA0002

T1203Exploitation for Client Execution×1

Adversaries may exploit software vulnerabilities in client applications to execute code. Vulnerabilities can exist in software due to unsecure coding practices that can lead to unanticipated behavior. Adversaries can take advantage of certain vulnerabilities through targeted exploitation for the purpose of arbitrary code execution. Oftentimes the most valuable exploits to an offensive toolkit are those that can be used to obtain code execution on a remote system because they can be used to gain access to that system. Users will expect to see files related to the applications they commonly used to do work, so they are a useful target for exploit research and development because of their high utility.

Evidence: 2026-09-04/cve-2026-85046-chrome-v8-type-confusion-exploited · ATT&CK page ↗

Story timeline

  1. 2026-09-04CVE-2026-85046, Google Chrome: V8 type confusion exploited in the wild via a crafted HTML page
    trending-vulnerabilitiesGoogle ships an emergency Chrome update for a V8 flaw it says is already being exploited

Where this entity is cited

  • trending-vulnerabilities1

Source distribution

  • chromereleases.googleblog.com1 (33%)
  • cveawg.mitre.org1 (33%)
  • services.nvd.nist.gov1 (33%)

Co-occurring entities

Derived: referenced by the same focused operational entries (weekly summaries and report roundups don't count); ×N counts the shared entries.

Entries about Google Chrome Compositing use-after-free, High severity, no reported exploitation (1)

2026-09-04 · view entry permalink →

HIGHCVE-2026-85046 +11exploitedNATOA2

CVE-2026-85046, Google Chrome: V8 type confusion exploited in the wild via a crafted HTML page

Google's Chrome 152.0.7977.82/.83 Stable release (2026-09-03) fixes 12 security bugs, headed by CVE-2026-85046, a type-confusion flaw in the V8 JavaScript engine (CWE-843) that a remote attacker triggers via a crafted HTML page, reaching arbitrary code execution inside the Chrome renderer sandbox (Google Chrome Releases, 2026-09-03). Google's own release notes state plainly that "Google is aware that an exploit for CVE-2026-85046 exists in the wild," and, per its standard restricted-disclosure practice, withholds further technical detail until most users have updated. The bug (Chromium issue 542403045) was reported by external researcher Salvatore Gulizia ("Serotav") on 2026-08-04. CISA's ADP Vulnrichment program scores it CVSS 3.1 8.8 (AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H), network vector, low complexity, no privileges, but requiring the victim to open the malicious page; neither Google nor MITRE, the CVE's assigning CNA, publishes its own numeric score.

The type confusion is a sandbox-escape primitive, not a full chain by itself: code that runs from it stays confined to the renderer sandbox, so full host compromise would need a second bug to escape it, or a target Chromium-based application running with reduced sandboxing, no source describes such chaining for this CVE as of publication. The remaining 11 fixes in the same release (9 High- and 2 Medium-severity issues across V8, Compositing, WebGL, Skia, DevTools, CacheStorage, CrashReporting, Network, Mobile and the Transactions Platform, most found by Google's own security team) carry no exploitation report from Google.

Google is aware that an exploit for CVE-2026-85046 exists in the wild.

Google Chrome Releases 2026-09-03

Type confusion in V8 in Google Chrome prior to 152.0.7977.82 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page.

MITRE CVE Program (Chrome as CNA) 2026-09-03
vulnerability04 Sep 05:00Zsingle-sourceOpen finding ↗