Active Exploitation of Chrome V8 Zero-Day Vulnerability CVE-2026-85046

Active Exploitation of Chrome V8 Zero-Day Vulnerability CVE-2026-85046

First seen 4 Sep 2026, 08:45 UTC ExpressSecurityweekMalwarebytesMirrorCisecurity+9 76.5

Article Content

Browse articles
ThreatCluster

Google has released a critical update for Chrome to address 12 vulnerabilities, including CVE-2026-85046, a type confusion flaw in the V8 JavaScript engine that is actively being exploited. This vulnerability allows remote attackers to execute arbitrary code within the browser's sandbox via specially crafted HTML pages. The flaw was reported by security researcher Salvatore Gulizia on August 4, 2026, and has a CVSS score of 8.8. Google confirmed that an exploit for this vulnerability exists in the wild, marking it as the sixth actively exploited zero-day of 2026. Users are urged to update to Chrome version 152.0.7977.82/.83 for Windows and Mac, and 152.0.7977.82 for Linux. The update rollout is ongoing, and users of other Chromium-based browsers should also apply the fixes as they become available.

Key Points: • CVE-2026-85046 is a critical type confusion vulnerability in Chrome's V8 engine. • The flaw allows remote code execution via crafted HTML pages and is actively exploited. • Google has released updates to patch this vulnerability across all supported platforms.

Ask AI about this cluster

Timeline

2026-02-13
CVE-2026-2441 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE
2026-03-12
CVE-2026-3909 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE
2026-03-12
CVE-2026-3910 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE
2026-04-01
CVE-2026-5281 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE
2026-06-08
CVE-2026-11645 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE
2026-08-04
CVE-2026-85046 reported
Security researcher Salvatore Gulizia reported the type confusion flaw in V8, leading to arbitrary code execution.
Securityaffairs.Co
2026-09-01
Multiple vulnerabilities published
Google disclosed multiple vulnerabilities in Chrome, including CVE-2026-85046, ahead of the patch release.
Cisecurity
2026-09-01
CVE-2026-84353 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE
2026-09-01
CVE-2026-84352 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE
2026-09-01
CVE-2026-84347 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE