Chrome patches actively exploited V8 zero-day CVE-2026-85046

· opgehaald 07:56

Google fixed a High V8 type confusion (sixth in-the-wild Chrome 0-day of 2026) allowing sandbox RCE via crafted HTML. Stable ≥152.0.7977.82; CISA added it to the KEV catalog.

On 3–4 Sep 2026 Google’s Chrome desktop update addressed CVE-2026-85046, a High type confusion in V8 that lets a remote attacker run arbitrary code inside the browser sandbox via a crafted HTML page. Google stated an exploit exists in the wild — the sixth actively exploited Chrome zero-day of 2026. Fixed in 152.0.7977.82/.83 (Windows/Mac) and 152.0.7977.82 (Linux); the same note ships 11 other fixes but only 85046 is called out as in-the-wild. NVD lists CISA KEV with a Sep 18, 2026 remediation due date. Researcher Salvatore Gulizia (Serotav) reported the Maglev/TurboFan sort-reduction bug that can yield JS-heap arb r/w; Chromium issue details stay restricted while rollout proceeds. Full host compromise still needs a separate sandbox escape.