Google patched CVE-2026-85046, a high-severity type-confusion vulnerability in the Chromium V8 JavaScript and WebAssembly engine that is under active exploitation. A maliciously crafted webpage can trigger arbitrary code execution within the browser sandbox when visited. The issue affects Google Chrome versions earlier than 152.0.7977.82 and extends to Chromium-based browsers, including Microsoft Edge, Brave, and Opera; CISA added the flaw to its Known Exploited Vulnerabilities catalog.
Microsoft Edge also received fixes for multiple Chromium-derived vulnerabilities, including sandboxed and sandbox-escape code-execution flaws, an access-restriction bypass, and a V8 out-of-bounds write. Organizations should urgently update Chrome to 152.0.7977.82 or later and Edge on Windows to 152.0.4191.66 or later, while validating and patching other deployed Chromium-based browsers against their vendors' fixed releases.

See which actors are running it and whether you're in range.
4 events from the most recent confirmed update back to the earliest known activity.
Microsoft's September 11 advisory addressed multiple Chromium-derived vulnerabilities in Edge for Windows. Organizations were advised to upgrade to Microsoft Edge version 152.0.4191.66 or later.
Google patched the actively exploited CVE-2026-85046 V8 type-confusion flaw, which affects Chrome versions before 152.0.7977.82 and can enable code execution within the browser sandbox through a crafted webpage.
CISA added CVE-2026-85046, a high-severity type-confusion vulnerability in Chromium V8 that was assessed as actively exploited, to its Known Exploited Vulnerabilities catalog.
Multiple Chromium-derived vulnerabilities, including sandboxed and sandbox-escape code-execution flaws, were published; the referenced vulnerability publication date is September 3, 2026.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
Correlate live exploitation activity against the software you actually run, and see where you're exposed.
3 references tracked. Mallory keeps watching after this page renders.
cert.ug
Open sourcetenable.com
Open sourcecve.circl.lu
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.