---
schema: 1
kind: vulnerability
title: "CVE-2026-85046 — Google Chrome: V8 type confusion exploited in the wild via a crafted HTML page"
headline: "Google ships an emergency Chrome update for a V8 flaw it says is already being exploited"
summary: >
  Google's Chrome 152.0.7977.82/.83 Stable release (2026-09-03) fixes CVE-2026-85046, a V8 type-confusion
  flaw reachable by visiting a crafted HTML page, which Google states it is aware has an exploit in the
  wild. The same release closes 11 further High/Medium-severity bugs with no reported exploitation.
  Update every Chrome and Chromium-based browser install now.
discovered_at: "2026-09-04T05:00:00Z"
updated_at: null
event_date: "2026-09-03"
run_id: 2026-09-04T0410Z-intel
priority: high
immediate_action: null
tags: [vulnerabilities, zero-day, actively-exploited, rce, patch-available]
regions: [global]
sectors: [public-sector]
entities: []
techniques: [T1189, T1203]
affected_products: ["Google Chrome"]
cves:
  - id: CVE-2026-85046
    cvss: "8.8"
    epss: null
    type: rce
    vector: user-interaction
    auth: pre-auth
    status: [exploited, cisa-kev, patch-available]
    affected: "< 152.0.7977.82 (Linux) / < 152.0.7977.82-.83 (Windows/Mac)"
    fixed: "152.0.7977.82 (Linux) / 152.0.7977.82-.83 (Windows/Mac)"
  - id: CVE-2026-85045
    cvss: null
    epss: null
    type: memory-corruption
    vector: user-interaction
    auth: pre-auth
    status: [patch-available]
    affected: "< 152.0.7977.82"
    fixed: "152.0.7977.82"
  - id: CVE-2026-85042
    cvss: null
    epss: null
    type: memory-corruption
    vector: user-interaction
    auth: pre-auth
    status: [patch-available]
    affected: "< 152.0.7977.82"
    fixed: "152.0.7977.82"
  - id: CVE-2026-85043
    cvss: null
    epss: null
    type: info-disclosure
    vector: user-interaction
    auth: pre-auth
    status: [patch-available]
    affected: "< 152.0.7977.82"
    fixed: "152.0.7977.82"
  - id: CVE-2026-85044
    cvss: null
    epss: null
    type: memory-corruption
    vector: user-interaction
    auth: pre-auth
    status: [patch-available]
    affected: "< 152.0.7977.82"
    fixed: "152.0.7977.82"
  - id: CVE-2026-85047
    cvss: null
    epss: null
    type: logic-flaw
    vector: user-interaction
    auth: pre-auth
    status: [patch-available]
    affected: "< 152.0.7977.82"
    fixed: "152.0.7977.82"
  - id: CVE-2026-85048
    cvss: null
    epss: null
    type: memory-corruption
    vector: user-interaction
    auth: pre-auth
    status: [patch-available]
    affected: "< 152.0.7977.82"
    fixed: "152.0.7977.82"
  - id: CVE-2026-85049
    cvss: null
    epss: null
    type: memory-corruption
    vector: user-interaction
    auth: pre-auth
    status: [patch-available]
    affected: "< 152.0.7977.82"
    fixed: "152.0.7977.82"
  - id: CVE-2026-85050
    cvss: null
    epss: null
    type: memory-corruption
    vector: user-interaction
    auth: pre-auth
    status: [patch-available]
    affected: "< 152.0.7977.82"
    fixed: "152.0.7977.82"
  - id: CVE-2026-85051
    cvss: null
    epss: null
    type: memory-corruption
    vector: user-interaction
    auth: pre-auth
    status: [patch-available]
    affected: "< 152.0.7977.82"
    fixed: "152.0.7977.82"
  - id: CVE-2026-85052
    cvss: null
    epss: null
    type: info-disclosure
    vector: user-interaction
    auth: pre-auth
    status: [patch-available]
    affected: "< 152.0.7977.82"
    fixed: "152.0.7977.82"
  - id: CVE-2026-85053
    cvss: null
    epss: null
    type: info-disclosure
    vector: user-interaction
    auth: pre-auth
    status: [patch-available]
    affected: "< 152.0.7977.82"
    fixed: "152.0.7977.82"
sources:
  - url: "https://chromereleases.googleblog.com/2026/09/stable-channel-update-for-desktop_01882797386.html"
    publisher: "Google Chrome Releases"
    date: "2026-09-03"
    role: primary
  - url: "https://cveawg.mitre.org/api/cve/CVE-2026-85046"
    publisher: "MITRE CVE Program (Chrome as CNA)"
    date: "2026-09-03"
    role: primary
  - url: "https://services.nvd.nist.gov/rest/json/cves/2.0?cveId=CVE-2026-85046"
    publisher: "CISA ADP Vulnrichment (via NVD/MITRE record)"
    date: "2026-09-03"
    role: corroborating
closed_sources: []
evidence:
  - quote: "Google is aware that an exploit for CVE-2026-85046 exists in the wild."
    publisher: "Google Chrome Releases"
  - quote: "Type confusion in V8 in Google Chrome prior to 152.0.7977.82 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page."
    publisher: "MITRE CVE Program (Chrome as CNA)"
verification: single-source
sourcing_note: >
  Google is the primary disclosing party for its own product (Admiralty vendor-PSIRT carve-out).
  MITRE's CVE record derives from the same Google disclosure rather than independently observing
  the exploitation; neither Google nor MITRE (the CVE's assigning CNA) publishes its own numeric
  CVSS score. The 8.8 figure carried here is CISA's ADP Vulnrichment score (org id
  134c704f-9b21-4f2e-91b3-4a467353bcc0 in both the MITRE and NVD records) — NVD's own API response
  mirrors this same CISA-ADP metric rather than an independent NVD analyst assessment. That same
  CISA-ADP record's SSVC block carried an "Exploitation: none" decision point timestamped
  2026-09-03T00:00Z at the time of writing, before CISA listed the CVE as known-exploited on
  2026-09-04 and moved that decision point; it did not then reflect Google's same-day exploitation
  disclosure; this entry follows Google's own direct statement as the vendor's own first-party
  claim about its own product.
confidence: high
references: []
deep_dive: false
deep_dive_category: null
org_triage: null
classification:
  reliability: A
  credibility: 2
watchlist_hit: false
actions:
  - "Confirm Chrome auto-update policy is active fleet-wide (or push 152.0.7977.82+ via enterprise management) on every Windows, Mac and Linux endpoint, and check any Chromium-based browser in use (Edge, Brave, Vivaldi) for its own equivalent fix, since Google states an exploit for CVE-2026-85046 already exists in the wild."
updates:
  - at: "2026-09-06T14:05:00Z"
    run_id: 2026-09-06T1308Z-audit
    type: improvement
    internal: true
    summary: >
      CISA added CVE-2026-85046 to the Known Exploited Vulnerabilities catalog on 2026-09-04 and has
      since updated the CISA-ADP SSVC exploitation decision point that the sourcing note recorded as
      not yet reflecting Google's disclosure. The listing is recorded and the note updated; the entry
      already carried the flaw as exploited, so nothing changes for a reader.
    fields: [cves, sourcing_note]
migrated_from: null
---

Google's Chrome 152.0.7977.82/.83 Stable release (2026-09-03) fixes 12 security bugs, headed by CVE-2026-85046 — a type-confusion flaw in the V8 JavaScript engine (CWE-843) that a remote attacker triggers via a crafted HTML page, reaching arbitrary code execution inside the Chrome renderer sandbox ([Google Chrome Releases, 2026-09-03](https://chromereleases.googleblog.com/2026/09/stable-channel-update-for-desktop_01882797386.html)). Google's own release notes state plainly that "Google is aware that an exploit for CVE-2026-85046 exists in the wild," and, per its standard restricted-disclosure practice, withholds further technical detail until most users have updated. The bug (Chromium issue 542403045) was reported by external researcher Salvatore Gulizia ("Serotav") on 2026-08-04. CISA's ADP Vulnrichment program scores it CVSS 3.1 8.8 (AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H) — network vector, low complexity, no privileges, but requiring the victim to open the malicious page; neither Google nor MITRE, the CVE's assigning CNA, publishes its own numeric score.

The type confusion is a sandbox-escape primitive, not a full chain by itself: code that runs from it stays confined to the renderer sandbox, so full host compromise would need a second bug to escape it, or a target Chromium-based application running with reduced sandboxing — no source describes such chaining for this CVE as of publication. The remaining 11 fixes in the same release (9 High- and 2 Medium-severity issues across V8, Compositing, WebGL, Skia, DevTools, CacheStorage, CrashReporting, Network, Mobile and the Transactions Platform, most found by Google's own security team) carry no exploitation report from Google.

**Defender takeaway:** treat fleet-wide Chrome update verification as a today task, not the next patch cycle, given confirmed in-the-wild exploitation and the browser's ubiquity on administrative endpoints; extend the same check to every Chromium-based browser in use, since they share the V8 codebase and typically patch on a short lag behind Chrome's own release. Detection concepts: Google withholds exploit specifics, so the only generic tell available is EDR/browser-crash telemetry for anomalous Chrome renderer-process crashes or unexpected child-process spawns from a renderer shortly after the process visited an untrusted URL.
