- Sources: NVD record, CISA KEV, Chrome release note, discussion
- Summary: CVE-2026-85046 is a type confusion bug in V8 that CISA records as actively exploited, with a federal remediation due date of 2026-09-18. The NVD record scopes the defect to Google Chrome before 152.0.7977.82 and lists Chrome as the only affected product. The fixed version comes from that record because the Chrome Releases post body returned empty to automated fetch.
- Comments: The Hacker News title reads "Actively exploited sandbox RCE in all Chromium versions". The NVD description scopes execution to inside the sandbox and the affected product to Chrome before 152.0.7977.82, and the only CISA text reachable is the catalog name "Google Chromium V8 Type Confusion Vulnerability".
- Why it matters: Any fleet running Chrome needs the version bump, and the difference between execution inside the sandbox and a full escape changes how urgent the second-stage risk is.
- Follow-up: Watch for a chained sandbox escape and for any record widening the affected product list beyond Chrome.
send feedback on this story