Google Chrome V8 type confusion security flaw (CVE-2026-85046)
Vulnerability
Summary
Hide ▲
Show ▼
Google patched CVE-2026-85046, a V8 type confusion flaw in Google Chrome that was actively exploited in the wild and could let a remote attacker execute code inside the browser sandbox. The bug affected Chrome prior to 152.0.7977.82, and Google shipped fixes in 152.0.7977.82/.83 for Windows and Apple macOS and 152.0.7977.82 for Linux. The flaw was reachable through a crafted HTML page, making browser users exposed until they updated.
Related Happenings
Chrome V8 JavaScript engine out-of-bounds read/write zero-day exploited in the wild (CVE-2026-11645)
Vulnerability
H score45
First: 09.06.2026 09:56
Last: 09.06.2026 09:56
Sources 1
About this happening:
Google has patched CVE-2026-11645, a Chrome V8 JavaScript engine zero-day that was exploited in the wild and could let remote attackers run code inside the browser...
Chrome V8 JavaScript engine out-of-bounds read/write zero-day exploited in the wild (CVE-2026-11645)
VulnerabilityAbout this happening: Google has patched CVE-2026-11645, a Chrome V8 JavaScript engine zero-day that was exploited in the wild and could let remote attackers run code inside the browser...
Chromium JavaScript background RCE flaw
Vulnerability
H score16
First: 21.05.2026 21:13
Last: 21.05.2026 21:13
Sources 1
About this happening:
The unfixed Chromium flaw keeps JavaScript running after the browser is closed, creating remote code execution risk across Chromium-based browsers. A malicious sit...
Chromium JavaScript background RCE flaw
VulnerabilityAbout this happening: The unfixed Chromium flaw keeps JavaScript running after the browser is closed, creating remote code execution risk across Chromium-based browsers. A malicious sit...
Chrome/Dawn actively exploited use-after-free flaw (CVE-2026-5281)
Vulnerability
H score1
First: 01.04.2026 13:25
Last: 01.04.2026 13:25
Sources 1
About this happening:
Google Chrome Stable Desktop on Windows, macOS, and Linux is getting an emergency fix for CVE-2026-5281, a use-after-free flaw in Dawn/WebGPU. Google says...
Chrome/Dawn actively exploited use-after-free flaw (CVE-2026-5281)
VulnerabilityAbout this happening: Google Chrome Stable Desktop on Windows, macOS, and Linux is getting an emergency fix for CVE-2026-5281, a use-after-free flaw in Dawn/WebGPU. Google says...
Chrome Skia and V8 exploited zero-days (multiple vulnerabilities)
Vulnerability
H score31
First: 13.03.2026 11:17
Last: 13.03.2026 11:17
Sources 1
About this happening:
Chrome on Windows, macOS, and Linux is affected by two high-severity zero-days, CVE-2026-3909 and CVE-2026-3910, that Google says were exploited in the wild*...
Chrome Skia and V8 exploited zero-days (multiple vulnerabilities)
VulnerabilityAbout this happening: Chrome on Windows, macOS, and Linux is affected by two high-severity zero-days, CVE-2026-3909 and CVE-2026-3910, that Google says were exploited in the wild*...
Timeline
-
04.09.2026 10:18 2 articles · 4h ago
Google patches actively exploited Chrome zero-day CVE-2026-85046
Mitigation Patch UpdateGoogle releases security updates for Chrome, patching 12 vulnerabilities including CVE-2026-85046, and acknowledges that an exploit for the flaw exists in the wild; the bug affects Google Chrome prior to 152.0.7977.82, with fixes in 152.0.7977.82/.83 for Windows and Apple macOS and 152.0.7977.82 for Linux.
Show sources
- Google Releases Chrome Update to Patch Actively Exploited V8 Zero-Day — thehackernews.com — 04.09.2026 10:18
- Google Releases Chrome Update to Patch Actively Exploited V8 Zero-Day — thehackernews.com — 04.09.2026 10:18
-
04.08.2026 03:00 1 articles · 1mo ago
Researcher reports V8 type confusion flaw in Google Chrome
Initial DisclosureSecurity researcher Salvatore Gulizia (aka Serotav) discovers and reports CVE-2026-85046, a high-severity type confusion flaw in V8, Google Chrome's JavaScript and WebAssembly engine, that can let a remote attacker execute arbitrary code inside the sandbox via a crafted HTML page.
Show sources
- Google Releases Chrome Update to Patch Actively Exploited V8 Zero-Day — thehackernews.com — 04.09.2026 10:18