CVE-2026-85046KEV · due Sep 18CWE-843
Google Chromium V8 Type Confusion Vulnerability
High · published September 4, 2026
Patch now
Confirmed exploited, and the score agrees
CVSS calls it high at 8.8. It is confirmed in active exploitation. It sits in the 65.1th percentile for exploit probability.
What it is
Type confusion in V8 in Google Chrome prior to 152.0.7977.82 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: High)
The record
Technical detail
- CVSS v3.1
- 8.8 · HIGH
- Vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
- CVSS v4.0
- Not supplied
- EPSS
- 0.01162 · 65.1th percentile
- Weakness
- CWE-843 · Access of Resource Using Incompatible Type ('Type Confusion')
- Published
- 2026-09-04T00:17Z
- KEV added
- 2026-09-04 · due 2026-09-18
Affected products (1)
| Product | Versions | Fixed in |
|---|
| google/chrome | < 152.0.7977.82 | 152.0.7977.82 |
References (7)
EPSS history
Timeline