• CISA KEV
  • EXPLOITED
  • PoC PUBLIC
  • PATCH AVAILABLE

CVE-2026-85046: type confusion rce in Google Chromium V8

Remote attackers can execute arbitrary code in Chromium V8 when a user opens a crafted HTML page. CVE-2026-85046 is a type confusion flaw that allows code execution inside the sandbox; it affects Chromium V8 branch 152.x before 152.0.7977.82 and was fixed in 152.0.7977.82. An attacker needs network access to deliver a malicious page and requires user interaction (the victim must load or interact with the crafted content).

Published Updated Source: CVE Program, NVD, CISA KEV, FIRST EPSS

CVSS 3.1
8.8HIGH
EPSS
0.48881
CWE
CWE-843
KEV DUE DATE
PATCH
Available

DIRAS TAKE

Urgent: this defect is listed on CISA’s Known Exploited Vulnerabilities catalog with a federal remediation deadline, so prioritize updating or applying vendor mitigations immediately.

What is CVE-2026-85046?

Remote attackers can execute arbitrary code in Chromium V8 when a user opens a crafted HTML page. CVE-2026-85046 is a type confusion flaw that allows code execution inside the sandbox; it affects Chromium V8 branch 152.x before 152.0.7977.82 and was fixed in 152.0.7977.82. An attacker needs network access to deliver a malicious page and requires user interaction (the victim must load or interact with the crafted content).

Vector CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

Which versions of Google Chromium V8 are affected?

BRANCHAFFECTEDFIXED
152.x152.0.7977.82 – before 152.0.7977.82152.0.7977.82

Is CVE-2026-85046 being exploited?

CISA added this vulnerability to the Known Exploited Vulnerabilities catalog on 2026-09-04, and U.S. federal agencies were required to remediate it by 2026-09-18.

How to fix CVE-2026-85046

  1. Upgrade Chromium-based products to 152.0.7977.82 or later.
  2. If you cannot update immediately, restrict exposure by blocking or isolating affected clients from untrusted web content.
  3. Follow vendor guidance and apply any recommended mitigations.
  4. Monitor endpoint telemetry for crashes or suspicious renderer activity and review web gateway logs for exploitation attempts.

Frequently asked questions

Is CVE-2026-85046 being actively exploited?

CISA added CVE-2026-85046 to the Known Exploited Vulnerabilities catalog on 2026-09-04, and federal agencies were required to remediate it by 2026-09-18.

Which Chromium V8 versions are affected by CVE-2026-85046?

Chromium V8 branch 152.x versions before 152.0.7977.82 are affected; the issue is fixed in 152.0.7977.82.

Is there a patch for CVE-2026-85046?

Yes. The vulnerability is fixed in Chromium V8 version 152.0.7977.82.

Does CVE-2026-85046 require authentication?

No authentication is required; an attacker can deliver a crafted HTML page over the network, but the exploit requires user interaction to load or engage with the malicious content.

References