Google Chrome V8 Type Confusion Remote Code Execution Vulnerability (CVE-2026-85046)
A new zero-day Remote Code Execution vulnerability (CVE-2026-85046) was identified recently and impacting Google Chrome browsers. The vulnerability enables a remote unauthenticated attacker to achieve remote code execution inside the Chrome sandbox by serving a crafted HTML page. Google has stated that the vulnerability is actively exploited in the wild, users are urged to update their browsers to the latest version immediately to mitigate any potential threats.
Google Chrome V8 Type Confusion Remote Code Execution Vulnerability (CVE-2026-85046) It is a type confusion flaw in Chrome’s V8 JavaScript engine. Successful exploitation enables a remote, unauthenticated attacker to execute arbitrary code inside the sandbox by inducing a victim to load a malicious HTML page. No privileges on the target are required; user interaction is limited to visiting or rendering the attacker-controlled page (e.g. via a link, malvertising, or a compromised website)
It is a type confusion flaw in Chrome’s V8 JavaScript engine. Successful exploitation enables a remote, unauthenticated attacker to execute arbitrary code inside the sandbox by inducing a victim to load a malicious HTML page. No privileges on the target are required; user interaction is limited to visiting or rendering the attacker-controlled page (e.g. via a link, malvertising, or a compromised website)
Google Chrome prior to version 152.0.7977.82 (Windows)
Google Chrome prior to version 152.0.7977.82/83 (macOS)
Google Chrome prior to version 152.0.7977.82 (Linux)
Update the Google Chrome browsers (in Settings > Chrome ) to the latest version IMMEDIATELY .
Chrome Releases: Stable Channel Update for Desktop
Google Chrome Multiple Vulnerabilities (HKCERT)
Google Patches 5th Chrome Zero-Day Exploited in 2026 (SecurityWeek)
Published on: 4 Sep 2026
The full story
This article is one source in a clustered incident — the cluster page carries the summary, timeline and every other outlet covering it.
