Back
SiTech
CVE-2026-85046: Chrome patches an actively exploited type confusion in V8
SiTech AI Team2 წთ. საკითხავი

CVE-2026-85046: Chrome patches an actively exploited type confusion in V8

Google shipped a Chrome stable-channel update that closes a flaw in the V8 engine, which the company says is already exploited in the wild. CISA has added the vulnerability to its known exploited list.

Google shipped a Chrome stable-channel update on 3 September 2026 that closes a V8 engine flaw the company says is already being exploited in the wild. The vulnerability, tracked as CVE-2026-85046, is a type confusion in V8 — the JavaScript and WebAssembly engine that Chrome shares with other Chromium-based browsers.

What the flaw allows

The National Vulnerability Database describes it as a flaw that let a remote attacker "execute arbitrary code inside the sandbox via a crafted HTML page". It is classified as CWE-843, access of a resource using an incompatible type. CISA's scoring puts the CVSS 3.1 base score at 8.8 (High), with the vector AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H — reachable over the network and requiring no privileges, but dependent on a user opening a malicious page.

NVD lists the affected configurations as Chrome before 152.0.7977.82 and V8 before 15.3.48.

The exploit and the fix

Security researcher Salvatore Gulizia, who publishes as Serotav, reported the bug to Google on 4 August 2026 and received a $1,000 reward. He later published a technical writeup titled "When Sorting Leads to Confusion", describing the flaw in V8's Maglev compiler: an inlined insertion sort that replaces calls to Array.prototype.sort could leave an array holding non-integer elements carrying the map reserved for small integers, which he turned into arbitrary read and write on the JavaScript heap. The same bug was present in the Turbofan compiler as well, and he chained it with an n-day sandbox escape.

Google fixed the issue in the V8 commit e0562d87 and released Chrome 152.0.7977.82/.83 for Windows and macOS and 152.0.7977.82 for Linux. The update contains 12 security fixes in total, among them a second V8 issue — a race condition tracked as CVE-2026-85045 — plus flaws in Compositing, Skia, WebGL, DevTools and CacheStorage.

Why it matters

CISA added the vulnerability to its Known Exploited Vulnerabilities catalog on 4 September 2026 and gave US federal agencies until 18 September to apply mitigations under its risk-based patching directive. The catalog entry, filed as "Google Chromium V8 Type Confusion Vulnerability", requires agencies to apply vendor mitigations or discontinue use of the product where no mitigation exists.

Because V8 is shared by Chromium-based browsers, the correction concerns more than Chrome: every browser built on the engine needs the corresponding update. For users, the practical step is simple — restart the browser so the patch takes effect.

SSiTech

SiTech — AI-powered web development

We build fast, modern websites and bring AI into real business workflows. Have a project or a question? We'd love to help.