SUNDAY, SEPTEMBER 6, 2026|No. 14061
Cybersecurity · Vulnerability

Critical Sandbox Escape Vulnerability Actively Exploited in Chromium Browsers

A severe type confusion vulnerability in the V8 JavaScript engine of Chromium browsers is being actively exploited, allowing remote attackers to execute arbitrary code.

A digital representation of a browser's security shield being compromised.
A digital representation of a browser's security shield being compromised. · Photo by Chris Ried on Unsplash
3 sources
Pipeline ingest
3 reads
Positive / Neutral / Negative
0 countries
Related coverage

CVE-2026-85046 Detail

Modified After Enrichment

This CVE record has been updated after NVD enrichment efforts were completed. Enrichment data supplied by the NVD may require amendment due to these changes.

Description

Type confusion in V8 in Google Chrome prior to 152.0.7977.82 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: High)

Metrics

CVSS Version 4.0 CVSS Version 3.x CVSS Version 2.0 SSVC

NVD enrichment efforts reference publicly available information to associate vector strings. CVSS information contributed by other sources is also displayed.

CVSS 3.x Severity and Vector Strings:

NIST: NVD

Base Score: N/A

NVD assessment not yet provided.

ADP: CISA-ADP

Base Score:8.8 HIGH

Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

References to Advisories, Solutions, and Tools

URLSource(s)Tag(s)
https://chromereleases.googleblog.com/2026/09/stable-channel-update-for-desktop_01882797386.htmlChromeRelease NotesVendor Advisory
https://github.com/Serotav/Writeups/blob/77556c57999805fa7815a114da51d91cf24fbea9/v8/When_Sorting_Leads_To_Confusion.mdCVE
https://github.com/v8/v8/commit/e0562d87ad9c17042b581582c99237d798572e67CVE
https://issues.chromium.org/issues/542403045ChromePermissions Required
https://news.ycombinator.com/item?id=49570669CVE
https://serotav.github.io/Writeups/v8/when-sorting-leads-to-confusion/CVE
https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-85046CISA-ADPUS Government Resource

This CVE is in CISA's Known Exploited Vulnerabilities Catalog

Reference CISA's BOD 22-01 and Known Exploited Vulnerabilities Catalog for further guidance and requirements.

Vulnerability NameDate AddedDue DateRequired Action
Google Chromium V8 Type Confusion VulnerabilitySeptember 04, 2026September 18, 2026Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.

Weakness Enumeration

CWE-IDCWE NameSource
CWE-843Access of Resource Using Incompatible Type ('Type Confusion')Chrome

Known Affected Software Configurations

Configuration 1(hide)

cpe:2.3:a:google:chrome:*:*:*:*:*:*:*:*Show matching CPE(s)**Up to (excluding)**152.0.7977.82

Denotes Vulnerable Software

Are we missing a CPE here? Please let us know.

Affected Products

Source: Chrome(hide)

VendorProductVersions
GoogleChromeAffected 152.0.7977.82 < 152.0.7977.82

Change History

8 change records found show changes

Quick Info

CVE Dictionary Entry:

CVE-2026-85046

NVD Published Date:

Sep 03, 2026

NVD Last Modified:

Sep 06, 2026

Source:

Chrome

PAN's pipeline reviewed approximately 3 open sources for this article. No human editor reviewed this article before publication.

Related Reads

Show on timeline →