Fixing and finding
Jump to remediation plan
CVE ID

CVE-2026-85046

Published 2026-09-03
Updated yesterday
Vendor/s
Google
Product/s
Chromium V8
Version/s
* > 152.0.7977.82
KEV Status
Active Exploitation
Listed in CISA's Known Exploited Vulnerabilities catalog. Active exploitation observed in the wild.
CVSS Score (v3.1)
8.8
/ 10
High
Severity Details
Base score
8.8 High
Attack vector
Network
Attack complexity
Low
Privileges required
None
User interaction
Required
Scope
Unchanged
Confidentiality
High
Integrity
High
Availability
High

Description

CVE-2026-85046 is a high-severity (8.8) type confusion vulnerability in Google Chrome's V8 engine being actively exploited for remote code execution.

CPE

Google logo
Google
Product Version Start Version End (excl.) Status
chrome * 152.0.7977.82 vulnerable

Related weakness (CWE)

CWE-843

Remediation plan

1

Apply official patches

Immediately update Google Chrome to version 152.0.7977.82 or later. This update includes the necessary fixes for the V8 engine to prevent type confusion exploits.

2

Update affected systems

Identify and update all Chromium-based browsers and applications across the enterprise that are running versions prior to 152.0.7977.82, ensuring all endpoints are protected.

3

Restrict access

Utilize web filtering and secure web gateways to block access to known malicious or untrusted websites, reducing the risk of users encountering the crafted HTML pages required for exploitation.

4

Monitor for exploitation

Deploy endpoint detection and response (EDR) signatures to monitor for unusual browser process behavior, such as unexpected shell execution or memory allocation patterns indicative of a sandbox escape.

Detection Guidance

"Detection should focus on identifying outdated browser versions through asset inventory and vulnerability scanning. Organizations should monitor endpoint logs for frequent browser crashes or unusual child processes spawned by chrome.exe. Additionally, network security teams should inspect traffic for indicators of compromise (IOCs) related to known exploit kits and monitor for connections to suspicious domains that may host the malicious HTML pages used in this attack."

References

Sources

NIST National Vulnerability Database (NVD)
CISA Known Exploited Vulnerabilities (KEV)

Experience superior visibility and a simpler approach to cyber risk management