CVE-2026-85046KEV · due Sep 18CWE-843

Google Chromium V8 Type Confusion Vulnerability

High · published September 4, 2026

Patch now

Confirmed exploited, and the score agrees

CVSS calls it high at 8.8. It is confirmed in active exploitation. It sits in the 65.1th percentile for exploit probability.

11
days to CISA
deadline
CVSS v3.1
8.8
EPSS
1%
Percentile
65.1
In the wild
Confirmed
What it is

Type confusion in V8 in Google Chrome prior to 152.0.7977.82 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: High)

The record
Technical detail
CVSS v3.1
8.8 · HIGH
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
CVSS v4.0
Not supplied
EPSS
0.01162 · 65.1th percentile
Weakness
CWE-843 · Access of Resource Using Incompatible Type ('Type Confusion')
Published
2026-09-04T00:17Z
KEV added
2026-09-04 · due 2026-09-18
Affected products (1)
ProductVersionsFixed in
google/chrome< 152.0.7977.82152.0.7977.82
References (7)
EPSS history
Timeline
  • 05 SEP 03:44Z
    EPSS moved — → 0%
    epss
  • 04 SEP 00:00Z
    Added to CISA KEV — remediate by Sep 18
    kev
  • 03 SEP 19:26Z
    Type confusion in V8 in Google Chrome prior to 152.0.7977.82 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page
    cvelistv5