Actively exploited sandbox RCE in all Chromium versions

CVE-2026-85046 is a type confusion vulnerability in V8, the JavaScript engine of Chromium, affecting Google Chrome prior to version 152.0.7977.82. A remote attacker can exploit a crafted HTML page to execute arbitrary code inside the sandbox, with a CVSS score of 8.8 (High). The vulnerability is listed in CISA's Known Exploited Vulnerabilities Catalog, with a required action to apply vendor mitigations by September 18, 2026.

Type confusion in V8 in Google Chrome prior to 152.0.7977.82 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page.

More from this day

2026-09-04