CVE-2026-85046
HIGH · 8.8 KEV EPSS 1.3%KEV-listed, vendor patched emergently, active exploitation confirmed, mass update required
What: Type confusion in V8 JavaScript engine in Google Chrome prior to v152.0.7977.82 allows remote arbitrary code execution within the sandbox via crafted HTML. CVSS 8.8 (HIGH).
Why it matters: KEV-listed as of 2026-09-04; Google issued urgent patch within 24 hours of CVE publication. Social chatter consistently reports active exploitation in the wild across all Chromium versions. High-severity sandbox escape affecting billions of users demands immediate patching.
Where it's seen: Bluesky and Hacker News amplifying patch advisory and KEV status. Repetitive posts emphasize "actively exploited" and link to NVD/vendor guidance. No public PoC code shared yet, but urgency signals vendor awareness of ongoing abuse.
RISK: CRITICAL — Sandbox RCE, KEV-listed, actively exploited, billions of Chrome users affected
Description
Type confusion in V8 in Google Chrome prior to 152.0.7977.82 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: High)
CVSS 3.1 breakdown
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H- Attack vector
- Network
- Complexity
- Low
- Privileges required
- None
- User interaction
- Required
- Scope
- Unchanged
- Confidentiality
- High
- Integrity
- High
- Availability
- High