Vulnerability
Published 2026-09-04
Verified 2026-09-19

Chrome V8 type-confusion 0-day (CVE-2026-85046) exploited in the wild; 152.0.7977.82/.83

Google's Stable Channel Update for Desktop (4 September 2026) promotes Chrome to 152.0.7977.82/.83 on Windows and macOS and 152.0.7977.82 on Linux with 12 security fixes. High-severity CVE-2026-85046 is a type confusion in V8 that Google says allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page; Google states an exploit exists in the wild. NVD Secondary CVSS 3.1 is 8.8 (AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H). Salvatore Gulizia (Serotav) reported it on 4 August 2026. CISA added CVE-2026-85046 to KEV (catalog entry dated 4 September 2026). WA SOC advisory 20260907001 (7 September 2026, TLP:CLEAR) covers the same Chromium V8 type confusion for Chrome, Edge, Brave and Vivaldi prior to those builds, notes CISA KEV, and says it has not received reports of exploitation on Western Australian Government networks at the time of writing. Distinct from desk card chrome-firefox-20260902 (2 Sep Critical UAF batch at 152.0.7977.75/.76) and cve-2026-79290 (25 Aug Aura/ANGLE). UPDATE 9 Sep: Proofpoint BlueMoon exploit kit (desk card bluemoon-exploit-kit-20260909) chains this CVE with an un-CVE'd V8 sandbox escape and Windows CVE-2026-85880; APT31 first seen 28 Aug, then other espionage clusters. Update Chrome promptly; Chromium browsers (Edge, Brave, Opera, Vivaldi) should follow vendor builds.

Product
Google Chrome (V8)
Versions
Prior to 152.0.7977.82 (Linux) / 152.0.7977.82/.83 (Windows/macOS)
CVSS
(CVSS 3.1 NVD Secondary)
Exploited in Australia?
unknown
Patch to
Chrome 152.0.7977.82/.83 (Win/Mac) or 152.0.7977.82 (Linux) or later

Primary: Chrome Stable Channel Update for Desktop (4 Sep 2026) · Vendor: Google Chrome Releases · CVE: CVE-2026-85046, CVE-2026-79290, CVE-2026-85880 · WA SOC 20260907001 (7 Sep 2026; Chromium V8 CVE-2026-85046)

vulnerabilities cloud australia