THREAT OPS › CVEs › CVE-2026-85046
CVE-2026-85046 — Google Chromium V8 Type Confusion Vulnerability
Google Chromium V8 contains a type confusion vulnerability that allows a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. This vulnerability could affect multiple web browsers that utilize Chromium, including, but not limited to, Google Chrome, Microsoft Edge, and Opera.
Vulnerability details
- Affected productsChromium V8
- KEV remediation due2026-09-18
Related reporting
- 14th September – Threat Intelligence Reportcheckpoint_research
- Mind the (Patch) Gap: Multiple Chinese Threat Actors Chain 0-day Exploits in Chrome & Windowsvolexity
- Patch Tuesday - September 2026rapid7
- [NVD] CVE-2026-85046 (HIGH 8.8) — Type confusion in V8 in Google Chrome prior to 152.0.7977.82 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: High)nvd
- CISA Adds One Known Exploited Vulnerability to Catalogcisa_advisories
- [CISA KEV] CVE-2026-85046 — Google Chromium V8: Google Chromium V8 Type Confusion Vulnerabilitycisa_kev
- Google security advisory (AV26-883)cccs_ca
- Google Releases Chrome Update to Patch Actively Exploited V8 Zero-Daythehackernews