CVE-2026-85046 is a high-severity type-confusion vulnerability in V8, the JavaScript and WebAssembly engine used by Google Chrome. In Chrome versions earlier than 152.0.7977.82, an error in V8 Maglev and TurboFan compiler handling can assign an array with PACKED_ELEMENTS the map intended for PACKED_SMI_ELEMENTS. This type mismatch can yield JavaScript-heap memory disclosure and corruption primitives, including potential arbitrary read and write access. A remote attacker can trigger the condition by causing a victim to render crafted HTML content, resulting in arbitrary code execution within the Chrome renderer sandbox. Exploitation in the wild has been confirmed.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
No public exploits tracked yet. Mallory keeps watching.
No public exploit code observed for this vulnerability.
28 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A high-severity type-confusion vulnerability in the V8 engine of Google Chrome before version 152.0.7977.82. A remote attacker can use a crafted HTML page to execute arbitrary code within Chrome's sandbox; the underlying compiler issue can be developed into arbitrary JavaScript-heap read/write capability.
A V8 JIT compiler type-confusion vulnerability in Chrome/Chromium browsers. A crafted HTML page can enable arbitrary code execution within Chrome's renderer sandbox through JavaScript-heap arbitrary read/write primitives.
An actively exploited CVSS 8.8 type-confusion zero-day in Chrome's V8 JavaScript and WebAssembly engine. A crafted HTML page could allow remote arbitrary code execution within the browser sandbox.
A high-severity type-confusion vulnerability in Chrome's V8 JavaScript and WebAssembly engine. A crafted HTML page can enable remote arbitrary code execution inside the Chrome sandbox. The flaw is actively exploited in the wild.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.