CVE-2026-85046
NVD HIGH 8.8 · published 2026-09-03 · 1 on the wire
Type confusion in V8 in Google Chrome prior to 152.0.7977.82 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: High)
Exploited in the wild
Yes
CISA added it 2026-09-04. An observation, not a forecast.
EPSS · 30-day forecast
1%
Chance of exploitation in the next 30 days, 72th percentile of all CVEs. A forecast; KEV outranks it.
CVSS · NVD
8.8
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Internet exposure
—
No exposure census on this CVE's dispatches.
On the wire1
- nvd.nist.gov ↗
- cisa.gov · KEV catalogue ↗
- first.org · EPSS ↗
- chromereleases.googleblog.com/2026/09/stable-channel-update-for-desktop_01882797386.html ↗
- issues.chromium.org/issues/542403045 ↗
- github.com/Serotav/Writeups/blob/77556c57999805fa7815a114da51d91cf24fbea9/v8/When_Sorting_Leads_To_Confusion.md ↗
- github.com/v8/v8/commit/e0562d87ad9c17042b581582c99237d798572e67 ↗
- news.ycombinator.com/item?id=49570669 ↗
Early access
Watch this one?
Early access opens alerts first — one email when a CVE you follow lands on KEV or an adversary you follow lands on the wire. Nothing else, ever.
bot-protected