CVE-2026-85046 Detail
Modified After Enrichment
This CVE record has been updated after NVD enrichment efforts were completed. Enrichment data supplied by the NVD may require amendment due to these changes.
Description
Type confusion in V8 in Google Chrome prior to 152.0.7977.82 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: High)
Metrics
CVSS Version 4.0 CVSS Version 3.x CVSS Version 2.0 SSVC
NVD enrichment efforts reference publicly available information to associate vector strings. CVSS information contributed by other sources is also displayed.
CVSS 3.x Severity and Vector Strings:
NIST: NVD
Base Score: N/A
NVD assessment not yet provided.
ADP: CISA-ADP
Base Score:8.8 HIGH
Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
References to Advisories, Solutions, and Tools
This CVE is in CISA's Known Exploited Vulnerabilities Catalog
Reference CISA's BOD 22-01 and Known Exploited Vulnerabilities Catalog for further guidance and requirements.
| Vulnerability Name | Date Added | Due Date | Required Action |
|---|---|---|---|
| Google Chromium V8 Type Confusion Vulnerability | September 04, 2026 | September 18, 2026 | Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines. |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-843 | Access of Resource Using Incompatible Type ('Type Confusion') | Chrome |
Known Affected Software Configurations
Configuration 1(hide)
| cpe:2.3:a:google:chrome:*:*:*:*:*:*:*:*Show matching CPE(s) | **Up to (excluding)**152.0.7977.82 |
Denotes Vulnerable Software
Are we missing a CPE here? Please let us know.
Affected Products
Source: Chrome(hide)
| Vendor | Product | Versions |
|---|---|---|
| Chrome | Affected 152.0.7977.82 < 152.0.7977.82 |
Change History
8 change records found show changes
Quick Info
CVE Dictionary Entry:
NVD Published Date:
Sep 03, 2026
NVD Last Modified:
Sep 06, 2026
Source:
Chrome




