CVE-2026-85046, a CVSS 8.8 type-confusion vulnerability in Chromium’s V8 JavaScript engine, was added to CISA’s Known Exploited Vulnerabilities (KEV) catalog on September 4, 2026. NVD’s vector shows a network-exploitable flaw requiring user interaction (visiting a malicious page) but no privileges, with high impact to confidentiality, integrity, and availability once triggered.
What the vulnerability does
NVD tracks CVE-2026-85046 under CWE-843 (Type Confusion). Per NVD’s description, the flaw affects V8 in Google Chrome prior to version 152.0.7977.82 and allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page — Chromium’s own severity rating (also cited in NVD’s reference data) classifies it as “High.” Google’s fix landed in the September 2026 stable-channel release; a public technical write-up analyzing the bug’s root cause is also linked from NVD’s reference data.
Why it’s on KEV
CISA’s September 4 KEV addition requires federal civilian agencies to remediate under BOD 26-04. Because “inside the sandbox” is explicit in Chromium’s own description, this specific CVE grants code execution within Chrome’s renderer sandbox — not an automatic sandbox escape to the host OS — though it is a common and valuable first stage for exploit chains that pair it with a separate sandbox-escape bug.
What we don’t yet have
CVSS scoring and the vulnerability description trace to NVD alone in our pipeline, with no second independent source yet corroborating the 8.8 figure — confidence on severity is marked medium, though exploitation status via CISA KEV is well-supported. We don’t have an EPSS score ingested for this CVE, nor confirmation of whether the KEV addition reflects exploitation in the wild as a standalone bug or as part of a chained exploit alongside a separate sandbox-escape flaw.
Why this matters
A CVE requiring only that a user load a malicious web page — Chrome’s most common and least defensible attack surface — landing on KEV means unpatched instances are exposed simply through ordinary browsing. This is one of two Chromium V8 CVEs added to KEV within five days of each other in September 2026: CVE-2026-87491, an out-of-bounds write also in V8, followed on September 9. Both affect the same engine component and both require the browser to render attacker-controlled content — organizations should confirm Chrome auto-update is functioning rather than treating either as an isolated one-off patch.
Frequently Asked Questions
What is CVE-2026-85046? A CVSS 8.8 type-confusion vulnerability in Chromium’s V8 engine (Chrome before 152.0.7977.82) that lets a remote attacker execute code inside Chrome’s sandbox via a crafted HTML page.
Is CVE-2026-85046 being actively exploited? Yes — CISA added it to the Known Exploited Vulnerabilities catalog on September 4, 2026.
What should Chrome users do? Confirm Chrome has updated to 152.0.7977.82 or later; Chrome auto-updates by default, but organizations managing Chrome centrally should verify the update has actually applied fleet-wide.
Data sourced from the National Vulnerability Database (NVD) and CISA’s Known Exploited Vulnerabilities (KEV) catalog, aggregated September 6, 2026. See more vulnerability intelligence.