CVE-2026-85046: Type confusion in V8
Published Aug 4, 2026
·Updated
Type confusion in V8 in Google Chrome prior to 152.0.7977.82 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: High)
Credit
Salvatore Gulizia (nickname: Serotav)
Affected Software
3 affected componentsFixes available
Google Chrome<152.0.7977.82
Google V8
Google Chrome<152.0.7977.82
152.0.7977.82
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 152.0.7977.82
Event History
Aug 4, 2026
CVE Published
12:00 AM
Known Exploited
12:00 AM
Data Sourced
12:00 AM
WeaknessAffected Software
Sep 3, 2026
CVE Published
via MITRE·07:26 PM
Data Sourced
via MITRE·07:26 PM
DescriptionWeakness
Peer vulnerabilities
Found alongside the following vulnerabilities.
Frequently Asked Questions
1
Which Chrome versions are affected?
Google Chrome versions prior to 152.0.7977.82 are affected. Update Chrome to 152.0.7977.82 or later.
2
What does an attacker need to exploit this vulnerability?
An attacker needs to induce the target to process a crafted HTML page remotely. Successful exploitation allows arbitrary code execution inside the Chrome sandbox.
3
Is there evidence of active exploitation?
Yes. The vulnerability is flagged as exploited and was added to the KEV list on 2026-08-04.