SATURDAY, SEPTEMBER 5, 2026|No. 13862
Cybersecurity · Vulnerability

Critical Chromium Vulnerability Actively Exploited, Prompt Patching Advised

A high-severity remote code execution vulnerability in Chromium's V8 engine is being actively exploited, prompting urgent security advisories and updates.

A padlock icon overlays a computer screen displaying code, symbolizing digital security.
A padlock icon overlays a computer screen displaying code, symbolizing digital security. · Photo by FlyD on Unsplash
1 sources
Pipeline ingest
3 reads
Positive / Neutral / Negative
0 countries
Related coverage

CVE-2026-85046 Detail

Description

Type confusion in V8 in Google Chrome prior to 152.0.7977.82 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: High)

Metrics

CVSS Version 4.0 CVSS Version 3.x CVSS Version 2.0 SSVC

NVD enrichment efforts reference publicly available information to associate vector strings. CVSS information contributed by other sources is also displayed.

CVSS 3.x Severity and Vector Strings:

NIST: NVD

Base Score: N/A

NVD assessment not yet provided.

ADP: CISA-ADP

Base Score:8.8 HIGH

Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

References to Advisories, Solutions, and Tools

URLSource(s)Tag(s)
https://chromereleases.googleblog.com/2026/09/stable-channel-update-for-desktop_01882797386.htmlChromeRelease NotesVendor Advisory
https://issues.chromium.org/issues/542403045ChromePermissions Required
https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-85046CISA-ADPUS Government Resource

This CVE is in CISA's Known Exploited Vulnerabilities Catalog

Reference CISA's BOD 22-01 and Known Exploited Vulnerabilities Catalog for further guidance and requirements.

| Vulnerability Name | Date Added | Due Date | Required Action 1. Remove site chrome: The provided text includes a lot of site-specific information like .gov badges, HTTPS icons, laboratory names, and navigation links. These are not part of the core article content and should be removed. The main article content starts with the CVE detail. The references and other sections are also part of the article's informational content. The introductory text about .gov and HTTPS is also site chrome. The

PAN's pipeline reviewed approximately 1 open sources for this article. No human editor reviewed this article before publication.

Related Reads

Show on timeline →