Description
Type confusion in V8 in Google Chrome prior to 152.0.7977.82 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: High)
In plain language
AI Act nowGoogle Chrome versions before 152.0.7977.82 have a flaw that can let attackers run code in the browser’s sandbox when a victim visits a specially crafted web page—this is confirmed being exploited in the real world, so a typical small business should update immediately.
In Google Chrome prior to 152.0.7977.82, a V8 type confusion flaw can be triggered by a crafted HTML page to gain remote code execution inside the browser sandbox (no login required; user interaction is required via visiting the page).
What to do now
- Check your Chrome version on each computer used for business (Chrome → Settings → About Chrome) and identify any system running a version prior to 152.0.7977.82.
- Update Google Chrome to 152.0.7977.82 or later on every affected machine.
- If you cannot update immediately, stop users from browsing with affected Chrome versions until updates can be applied, and block access to untrusted or newly seen websites as an interim control.
- After updating, review browser/device logs for signs of unusual browsing activity around the time you suspect exposure.
CVSS Vector Breakdown
AV:NAttack VectorAC:LAttack ComplexityPR:NPrivileges RequiredUI:RUser InteractionS:UScopeC:HConfidentialityI:HIntegrityA:HAvailabilityWeaknesses
Affected Products
Exploitability
Required action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
Attack Graph
Click technique nodes for MITRE ATT&CK details · drag to pan · Ctrl/⌘ + scroll to zoom, or go fullscreen.
MITRE ATT&CK
2 techniquesReferences
- ⚡ Weekly Recap: Chrome 0-Day, Router Hijacks, Coder Supply Chain Attack and Moreen·The Hacker News·
- В браузере Chrome исправили шестую 0-day-уязвимость в этом годуru-ru·Хакер (xakep.ru)·
- Google patches actively exploited Chrome zero-day (CVE-2026-85046)en-us·Help Net Security· Exploited Chrome zero-day
- Google warns of new Chrome zero-day flaw exploited in attacksen-us·BleepingComputer· Exploited Chrome zero-day
- Google Patches 6th Chrome Zero-Day of 2026en-us·SecurityWeek· Exploited Chrome zero-day
- Google Releases Chrome Update to Patch Actively Exploited V8 Zero-Dayen·The Hacker News· Exploited Chrome zero-day
- September 2026 Patch Tuesday forecast: All we need is more timeen-us·Help Net Security· Exploited SharePoint rce
Unlock Complete Vulnerability Intelligence
Get the full picture for CVE-2026-85046 and every CVE in our database. Create a free account — no credit card required.
Create Free Account