CTIPilot
← Back to Daily brief 2026-09-04
HIGHCVE-2026-85046 +11exploitedNATOA2vulnerability

CVE-2026-85046, Google Chrome: V8 type confusion exploited in the wild via a crafted HTML page

Google ships an emergency Chrome update for a V8 flaw it says is already being exploited

Defender actions

  • Confirm Chrome auto-update policy is active fleet-wide (or push 152.0.7977.82+ via enterprise management) on every Windows, Mac and Linux endpoint, and check any Chromium-based browser in use (Edge, Brave, Vivaldi) for its own equivalent fix, since Google states an exploit for CVE-2026-85046 already exists in the wild.

Analysis

Google's Chrome 152.0.7977.82/.83 Stable release (2026-09-03) fixes 12 security bugs, headed by CVE-2026-85046, a type-confusion flaw in the V8 JavaScript engine (CWE-843) that a remote attacker triggers via a crafted HTML page, reaching arbitrary code execution inside the Chrome renderer sandbox (Google Chrome Releases, 2026-09-03). Google's own release notes state plainly that "Google is aware that an exploit for CVE-2026-85046 exists in the wild," and, per its standard restricted-disclosure practice, withholds further technical detail until most users have updated. The bug (Chromium issue 542403045) was reported by external researcher Salvatore Gulizia ("Serotav") on 2026-08-04. CISA's ADP Vulnrichment program scores it CVSS 3.1 8.8 (AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H), network vector, low complexity, no privileges, but requiring the victim to open the malicious page; neither Google nor MITRE, the CVE's assigning CNA, publishes its own numeric score.

The type confusion is a sandbox-escape primitive, not a full chain by itself: code that runs from it stays confined to the renderer sandbox, so full host compromise would need a second bug to escape it, or a target Chromium-based application running with reduced sandboxing, no source describes such chaining for this CVE as of publication. The remaining 11 fixes in the same release (9 High- and 2 Medium-severity issues across V8, Compositing, WebGL, Skia, DevTools, CacheStorage, CrashReporting, Network, Mobile and the Transactions Platform, most found by Google's own security team) carry no exploitation report from Google.

Cited evidence

Google is aware that an exploit for CVE-2026-85046 exists in the wild.

Google Chrome Releases 2026-09-03

Type confusion in V8 in Google Chrome prior to 152.0.7977.82 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page.

MITRE CVE Program (Chrome as CNA) 2026-09-03

Sources3

PROVENANCE

AI-generated · no human review · this permalink is the shareable record for the finding · verify operationally critical claims against the linked primary source.