CVE-2026-85046 is a high-severity (8.8) type confusion vulnerability in Google Chrome's V8 engine being actively exploited for remote code execution.
| Product | Version Start | Version End (excl.) | Status |
|---|---|---|---|
| chrome | * | 152.0.7977.82 | vulnerable |
Immediately update Google Chrome to version 152.0.7977.82 or later. This update includes the necessary fixes for the V8 engine to prevent type confusion exploits.
Identify and update all Chromium-based browsers and applications across the enterprise that are running versions prior to 152.0.7977.82, ensuring all endpoints are protected.
Utilize web filtering and secure web gateways to block access to known malicious or untrusted websites, reducing the risk of users encountering the crafted HTML pages required for exploitation.
Deploy endpoint detection and response (EDR) signatures to monitor for unusual browser process behavior, such as unexpected shell execution or memory allocation patterns indicative of a sandbox escape.
"Detection should focus on identifying outdated browser versions through asset inventory and vulnerability scanning. Organizations should monitor endpoint logs for frequent browser crashes or unusual child processes spawned by chrome.exe. Additionally, network security teams should inspect traffic for indicators of compromise (IOCs) related to known exploit kits and monitor for connections to suspicious domains that may host the malicious HTML pages used in this attack."
Experience superior visibility and a simpler approach to cyber risk management