ZeroHour

CVE-2026-85045

mass

Race condition in Google Chrome V8 allows sandboxed code execution via crafted web page

CVSS 3.1
7.5 high
EPSS
<1%p12
Published
()
Modified
AI analysis

CVE-2026-85045 is a race condition (CWE-367, a time-of-check-to-time-of-use flaw) in the V8 JavaScript engine used by Google Chrome. An attacker triggers it by persuading a user to open a specially crafted HTML page, in which a timing window during V8's handling of an object leaves stale state that the attacker can leverage. Successful exploitation lets a remote attacker execute arbitrary code inside Chrome's renderer sandbox (but not escape it), yielding code execution at the browser's sandboxed privilege level; CVSS 3.1 rates this 7.5 High with a network vector, high attack complexity, and required user interaction. All Google Chrome installations running versions prior to 152.0.7977.82 are affected, which given Chrome's ubiquity means effectively every unpatched desktop and mobile Chrome deployment worldwide. No public proof-of-concept is known, the flaw is not on the CISA KEV catalog, and EPSS estimates a ~0.2% chance of exploitation within 30 days, though related reporting describes a sibling Chrome zero-day (CVE-2026-85046) exploited in the wild, signaling active attacker interest in this V8 code.

What to do: Update Google Chrome to 152.0.7977.82 or later on all endpoints and enforce the minimum version centrally (MDM/GPO/Intune/EDR), prioritizing internet-facing and high-risk users. Because the related Chrome zero-day CVE-2026-85046 was reportedly exploited in the wild and was addressed in the same release, treat this patch cycle as urgent. Also verify browser versions in any Chromium-based derivatives in your fleet, which typically pick up the V8 fix on their own release schedules.

Affected
google chromeall versions prior to 152.0.7977.82
Estimated exposure
massbillions of Chrome users/installations worldwide (Chrome holds roughly two-thirds desktop browser market share and 3+ billion users) — Chrome is the world's most widely deployed browser, so the pool of potentially exposed systems is effectively every user or fleet still running a pre-152.0.7977.82 build until patched; this is an order-of-magnitude estimate from public…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Race condition in V8 in Google Chrome prior to 152.0.7977.82 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: High)

Vendors
google
Products
chrome
Weakness
CWE-367
Vector
CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H

In the news

Google Chrome Zero-day Vulnerability Exploited in the Wild (CVE-2026-85046)

Google patched 12 Chrome flaws including in-the-wild V8 zero-day CVE-2026-85046; CISA added it to the KEV catalog.

Google released Chrome 152.0.7977.82/.83 for Windows and Mac (152.0.7977.82 for Linux) fixing 12 vulnerabilities, including CVE-2026-85046, a type confusion flaw in the V8 JavaScript engine being exploited in the wild. CISA added CVE-2026-85046 to its Known Exploited Vulnerabilities Catalog with a patch deadline of September 18, 2026. This is Chrome's sixth zero-day patched in 2026, following CVE-2026-2441, CVE-2026-3909, CVE-2026-3910, CVE-2026-5281 and CVE-2026-11645. The other 11 fixes include use-after-free, out-of-bounds, race condition and input validation flaws in Skia, WebGL, DevTools, Network, Compositing and other components.

Microsoft breaks Patch Tuesday record with 974-CVE deluge

Microsoft's record 974-CVE Patch Tuesday ships two exploited Windows zero-days, while Adobe's StyleSmuggler zero-day (CVE-2026-75650) gives unauthenticated RCE in Magento.

Microsoft's September Patch Tuesday addresses 974 CVEs, including two zero-days already under exploitation: CVE-2026-85880, a Windows ALPC privilege escalation leading to SYSTEM via sandbox escape, and CVE-2026-81963, a Windows Update Stack privilege escalation. Adobe patched 172 CVEs, including the max-severity StyleSmuggler zero-day CVE-2026-75650 in Magento and Adobe Commerce, which Sansec reports is being exploited since September 4 to inject PHP into templates and install a C2-connected backdoor. CISA added CVE-2026-85880, CVE-2026-81963, and CVE-2026-75650 to its Known Exploited Vulnerabilities Catalog with patch deadlines of September 22 and September 11. The piece also notes Google-patched Chrome V8 zero-day CVE-2026-85046 lacks a Microsoft advisory for Edge, and flags nine Exchange Server flaws including remote unauthenticated RCE CVE-2026-55007.

Patch Tuesday - September 2026

Microsoft's September 2026 Patch Tuesday fixes 999 CVEs, a record, with two zero-day privilege escalation flaws already exploited in the wild.

Microsoft published 974 own-product vulnerabilities plus 25 non-Microsoft CVEs, totaling 999 — the most CVEs Microsoft has ever released in a single day. Two flaws are exploited in the wild: CVE-2026-85880, an out-of-bounds write in Windows ALPC granting SYSTEM privileges, and CVE-2026-81963, an improper link resolution flaw in the Windows Update Stack also leading to SYSTEM. Chrome's V8 zero-day CVE-2026-85046 was patched in Edge on September 2, but Microsoft had not published a corresponding advisory, leaving uncertainty about other Chromium fixes in Edge. October 14 lifecycle changes end servicing for Windows 11 24H2 Home/Pro, Office 2021, and Exchange Server 2016/2019.

Rapid7 Blog · 7d agoVulnerability in the wildCVE-2026-85880CVE-2026-81963CVE-2026-85046+10 CVEs