CVE-2026-85046 · CVSS 8.8 HIGH · KEV 2026-09-04 · patch available
Type confusion in V8 in Google Chrome prior to 152.0.7977.82 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: High)
Is CVE-2026-85046 exploited?
Listed in the CISA KEV catalog on 2026-09-04.
Federal remediation due 2026-09-18.
Public exploit code: none found in monitored sources.
Which products and versions are affected?
Google · Chrome · <152.0.7977.82
Google · Chrome · <152.0.7977.83
Microsoft · Edge · <152.0.4191.65
Google · Chrome · >= 152.0.7977.82, < 152.0.7977.82
Microsoft · Microsoft Edge (Chromium-based) · < 152.0.4191.62