Type confusion in V8 in Google Chrome prior to 152.0.7977.82 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: High)
References
| Link | Resource |
|---|---|
| https://chromereleases.googleblog.com/2026/09/stable-channel-update-for-desktop_01882797386.html | Release Notes Vendor Advisory |
| https://issues.chromium.org/issues/542403045 | Permissions Required |
| https://github.com/Serotav/Writeups/blob/77556c57999805fa7815a114da51d91cf24fbea9/v8/When_Sorting_Leads_To_Confusion.md | Exploit Third Party Advisory |
| https://github.com/v8/v8/commit/e0562d87ad9c17042b581582c99237d798572e67 | Patch |
| https://news.ycombinator.com/item?id=49570669 | Issue Tracking Third Party Advisory |
| https://serotav.github.io/Writeups/v8/when-sorting-leads-to-confusion/ | Exploit Third Party Advisory |
| https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-85046 | US Government Resource |
Configurations
History
No history.
Information
Published : 2026-09-03 20:17
Updated : 2026-09-08 14:55
NVD link : CVE-2026-85046
Mitre link : CVE-2026-85046
CVE.ORG link : CVE-2026-85046
JSON object : View
Products Affected
- v8
- chrome
CWE
CWE-843
Access of Resource Using Incompatible Type ('Type Confusion')
