CVE-2026-85046 Detail
Description
Type confusion in V8 in Google Chrome prior to 152.0.7977.82 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: High)
Metrics
CVSS Version 4.0 CVSS Version 3.x CVSS Version 2.0 SSVC
NVD enrichment efforts reference publicly available information to associate vector strings. CVSS information contributed by other sources is also displayed.
CVSS 3.x Severity and Vector Strings:
NIST: NVD
Base Score: N/A
NVD assessment not yet provided.
ADP: CISA-ADP
Base Score:8.8 HIGH
Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
References to Advisories, Solutions, and Tools
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://chromereleases.googleblog.com/2026/09/stable-channel-update-for-desktop_01882797386.html | Chrome | Release NotesVendor Advisory |
| https://issues.chromium.org/issues/542403045 | Chrome | Permissions Required |
| https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-85046 | CISA-ADP | US Government Resource |
This CVE is in CISA's Known Exploited Vulnerabilities Catalog
Reference CISA's BOD 22-01 and Known Exploited Vulnerabilities Catalog for further guidance and requirements.
| Vulnerability Name | Date Added | Due Date | Required Action 1. Remove site chrome: The provided text includes a lot of site-specific information like .gov badges, HTTPS icons, laboratory names, and navigation links. These are not part of the core article content and should be removed. The main article content starts with the CVE detail. The references and other sections are also part of the article's informational content. The introductory text about .gov and HTTPS is also site chrome. The




