ZeroHour
Story · 1 source · 1 articlefirst updated ()

Google patches actively exploited Chrome V8 zero-day CVE-2026-85046; CISA adds it to KEV with 2026-09-18 federal deadline

What's new: First merged dashboard entry for this story; no previous summary exists, so all items below are initial coverage.
Merged summary · glm-5.3-flash · rewritten as coverage arrives

Google fixed the actively exploited V8 type confusion zero-day CVE-2026-85046 (CWE-843, CVSS 8.8) in Chrome 152.0.7977.82/.83 (Windows/Mac) and 152.0.7977.82 (Linux). CISA added it to the KEV catalog on 2026-09-04, giving Federal Civilian Executive Branch…

Google shipped a Stable channel desktop Chrome update fixing CVE-2026-85046, an actively exploited type confusion flaw (CWE-843) in the V8 JavaScript and WebAssembly engine. The bug, reported by researcher Salvatore Gulizia on August 4, 2026, is rated high severity (CVSS 8.8) and allows a remote attacker to execute arbitrary code inside the browser sandbox via a crafted HTML page; The Hacker News describes the root cause as PACKED_ELEMENTS receiving a PACKED_SMI_ELEMENTS map, yielding arbitrary JavaScript heap read/write. Google confirmed an exploit exists in the wild, and CISA added the CVE to its Known Exploited Vulnerabilities catalog on September 4, 2026, noting that known ransomware campaign use is currently unknown. Under Binding Operational Directive 26-04, FCEB agencies must apply vendor mitigations by September 18, 2026, prioritize remediation on exposed assets, and check for pre-patch compromise; CISA urges all organizations to prioritize the patch. Chrome is directly affected. CISA's KEV entry lists Chromium-based browsers including Microsoft Edge and Opera, The Hacker News adds Brave and Vivaldi, and Cyber Security News notes other Chromium-based browsers may be impacted depending on their V8 version, so users of those browsers should track their vendors' updates. Fixed versions are Chrome 152.0.7977.82/.83 on Windows and macOS and 152.0.7977.82 on Linux (the Canadian Centre for Cyber Security's advisory AV26-883 Update 1 cites 152.0.7977.82). Malwarebytes additionally flags critical use-after-free flaws CVE-2026-84353 (Shared Tab Groups) and CVE-2026-84352 (WebGL) in the same release, which it says allow code execution outside the browser sandbox via crafted HTML pages, and cites HKCERT rating the overall risk as extremely high. Sources disagree on the total number of fixes in the release: Malwarebytes counts 26, while The Hacker News counts 12 and lists additional CVEs CVE-2026-2441, CVE-2026-3909, CVE-2026-3910, CVE-2026-5281 and CVE-2026-11645. The Hacker News says this is the sixth actively exploited Chrome zero-day patched in 2026. Users should update via Settings > About Chrome and restart the browser.

  • CVE-2026-85046: type confusion (CWE-843) in the Google Chromium V8 JavaScript/WebAssembly engine, rated high severity (CVSS 8.8); allows remote arbitrary code execution inside the browser sandbox via a crafted HTML page; reported by…
  • Actively exploited: Google confirmed an exploit exists in the wild, and CISA added the CVE to the KEV catalog on 2026-09-04 based on evidence of active exploitation; ransomware campaign use is listed as unknown.
  • Fixed versions: Chrome Stable 152.0.7977.82/.83 on Windows/macOS and 152.0.7977.82 on Linux (per Malwarebytes and The Hacker News); Canadian Centre for Cyber Security advisory AV26-883 Update 1 cites 152.0.7977.82.
  • CISA KEV/BOD 26-04: Federal Civilian Executive Branch agencies must apply vendor mitigations by 2026-09-18, prioritize remediation on exposed assets, and check for pre-patch compromise.
  • Affected browsers: Chrome directly affected; CISA's KEV entry lists Chromium-based browsers including Microsoft Edge and Opera; The Hacker News also names Brave and Vivaldi; Cyber Security News notes other Chromium browsers may be impacted…
  • Same Chrome release also fixed critical use-after-free flaws CVE-2026-84353 (Shared Tab Groups) and CVE-2026-84352 (WebGL), enabling code execution outside the browser sandbox via crafted HTML pages, per Malwarebytes; HKCERT rates the…
  • Discrepancy on fix count: Malwarebytes reports 26 fixed security issues; The Hacker News reports 12 vulnerabilities fixed and lists additional CVEs CVE-2026-2441, CVE-2026-3909, CVE-2026-3910, CVE-2026-5281, CVE-2026-11645.
  • The Hacker News counts CVE-2026-85046 as the sixth actively exploited Chrome zero-day patched in 2026.

Coverage timeline

  1. · 14d ago
    Malwarebytes Labs· 85
    Two critical Chrome flaws put users at risk on malicious websites

    Google patched 26 Chrome flaws, including two critical use-after-frees and an actively exploited V8 sandbox escape (CVE-2026-85046); update to 152.0.7977.82/.83.

Vulnerabilities in this storyAll →

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2026-11645
Out-of-Bounds Read/Write in Google Chrome V8 Enables In-Sandbox Code Execution

CVE-2026-11645 is an out-of-bounds read and write (CWE-125/CWE-787) in V8, the JavaScript engine used by Google Chrome and Chromium. A remote attacker triggers the flaw by luring a user to a crafted HTML page, where malicious script causes V8 to read and write outside allocated memory buffers. Successful exploitation allows the attacker to execute arbitrary code inside the browser's security sandbox, providing limited privileges within that process rather than full system compromise. All Google Chrome versions prior to 149.0.7827.103 are affected, along with the Chromium V8 component identified by CISA. The flaw is being exploited in the wild: CISA added it to the Known Exploited Vulnerabilities catalog on 2026-06-09, and related headlines describe an actively exploited Chrome V8 zero-day, though no public proof-of-concept is known and ransomware use is unconfirmed.

Do: Update Google Chrome to 149.0.7827.103 or later and restart the browser to load the patched V8, prioritizing systems exposed to untrusted web content; because the flaw is in CISA's KEV catalog, federal agencies must apply vendor mitigations or follow BOD 22-01 guidance within the required timeframe. Organizations running Chromium-derived browsers (e.g., Edge, Brave, Opera) should apply vendor updates that incorporate the patched V8 as they become available. Restricting browsing of untrusted sites from high-value systems is a reasonable interim measure, and no public exploit code is known at this time.

8.82% KEV
  • Google Chrome prior to 149.0.7827.103
  • Google Chromium V8 (as shipped in Chrome) prior to the 149.0.7827.103 Chrome release
massbillions of users (Chrome holds roughly two-thirds of global browser market share)
CVE-2026-2441
Use-After-Free in Google Chromium CSS Rendering Exposes Chrome, Edge, Opera Users

CVE-2026-2441 is a use-after-free (CWE-416) in Google Chromium's CSS handling that a remote attacker can trigger by getting a user's browser to process a crafted HTML page, potentially corrupting the heap. Successful exploitation yields a memory-corruption primitive in the browser; CVSS scoring is not yet available, but Chromium memory-safety flaws of this class can range from crashes to potential code execution depending on how the corruption is leveraged. Anyone running Chromium or a Chromium-based browser — Google Chrome, Microsoft Edge, Opera, and numerous embedded/branded browsers — is potentially affected, making the exposed population effectively all modern browser users. CISA added the flaw to the Known Exploited Vulnerabilities catalog on 2026-02-17, confirming it is being exploited in the wild; EPSS assigns a 22% probability of exploitation within 30 days (98th percentile), no public PoC is known, and any ransomware association is unknown. This lands amid an accelerating series of actively exploited Chrome zero-days in 2026 described in recent reporting, making rapid patching urgent.

Do: Update Chromium and every Chromium-based browser in your estate (Chrome, Edge, Opera, Brave, and embedded browsers) to the latest vendor-stable release — recent reporting places the current patched release at Chrome 153 — and verify installed versions via the browser's About/Settings page. Per CISA's KEV required action, apply mitigations per vendor instructions or follow BOD 22-01 guidance for cloud services, and discontinue use if mitigations are unavailable. Until patched, restrict high-risk users' browsing to trusted sites and monitor vendor advisories for the specific fixed build, since exact version details are not yet published in this data.

8.822% KEV PoC
  • Google Chromium
  • Google Chrome (Chromium-based)
  • Microsoft Edge (Chromium-based)
  • +1 more
massbillions of users (Chromium underpins Chrome alone at ~3B+ users, plus Edge, Opera, and dozens of embedded browsers)
CVE-2026-3909
Out-of-Bounds Write in Google Chrome's Skia Rendering Engine

CVE-2026-3909 is an out-of-bounds write (CWE-787) in the Skia graphics rendering library used by Google Chrome, which Google patched in Chrome 146.0.7680.75. A remote attacker can trigger the flaw by luring a user to visit a crafted HTML page, causing out-of-bounds memory access in the browser process; the High CVSS 8.8 score with high confidentiality, integrity, and availability impact indicates memory corruption with potentially serious consequences. All Google Chrome installations running versions prior to 146.0.7680.75 are affected, and because the vulnerability resides in the Skia engine, the vulnerable code is present in every Chrome install. CISA added the flaw to its Known Exploited Vulnerabilities catalog on 2026-03-13, indicating exploitation in the wild, though no public proof-of-concept is known and ransomware use is unknown. EPSS currently assigns a 1.6% probability of exploitation within the next 30 days (75th percentile).

Do: Update Google Chrome to version 146.0.7680.75 or later on all endpoints, prioritizing systems with privileged or high-risk users; confirm the updated version is deployed rather than relying on auto-update timing. As an interim mitigation, restrict web browsing on sensitive systems and warn users about visiting untrusted pages; federal agencies must apply the fix per BOD 22-01 requirements given the KEV listing.

8.82% KEV
  • Google Chrome (Skia rendering engine) all versions prior to 146.0.7680.75
  • Google Skia (as shipped in Google Chrome, per CISA) prior to Chrome 146.0.7680.75
massbillions of users (Chrome is the world's most widely used desktop and mobile browser)
CVE-2026-3910
Out-of-Bounds Memory Flaw in Google Chrome V8 Allows Sandboxed Code Execution

CVE-2026-3910 is an out-of-bounds memory flaw — CISA classifies it as improper restriction of operations within the bounds of a memory buffer — caused by an inappropriate implementation in the V8 JavaScript and WebAssembly engine used in Google Chrome. A remote attacker triggers it by luring a user to a crafted HTML page, so exploitation requires user interaction but no privileges or special conditions. Successful exploitation allows the attacker to execute arbitrary code inside the Chrome sandbox, which confines the compromise to the renderer process rather than the full system, but still exposes data and credentials handled within the browser session. Anyone running Google Chrome prior to 146.0.7680.75 — or a Chromium-based browser that embeds the vulnerable V8 code — is affected. The flaw is being actively exploited in the wild: CISA added it to the Known Exploited Vulnerabilities catalog on 2026-03-13, and it comes amid a string of actively exploited Chrome V8 zero-days that Google has fixed during 2026.

Do: Update Google Chrome to version 146.0.7680.75 or later immediately, and verify fleet versions rather than assuming auto-update has completed. Users of Chromium-derived browsers should install their vendor's update that incorporates the corresponding V8 fix. Federal organizations must follow the BOD 22-01 required action in the KEV catalog — apply vendor mitigations or discontinue use of affected versions if mitigations are unavailable.

8.82% KEV
  • google chrome prior to 146.0.7680.75 (fixed in 146.0.7680.75)
massbillions of users (Chrome's global installed base is estimated at over 3 billion, with roughly two-thirds browser market share)
CVE-2026-5281
Use-After-Free in Google Chrome's Dawn (WebGPU) Component Enables Arbitrary Code Execution

CVE-2026-5281 is a use-after-free vulnerability in Dawn, the WebGPU implementation in Google Chrome, that Google patched in Chrome 146.0.7680.178. It is triggered when a remote attacker serves a crafted HTML page and can leverage it after having already compromised the Chrome renderer process, escalating to arbitrary code execution beyond the initial foothold. Because the flaw requires a compromised renderer as a starting point, it is typically chained with another bug (such as a renderer-exploiting issue) to break out to arbitrary code execution with real impact on confidentiality, integrity, and availability. Any user or organization running Google Chrome on a version prior to 146.0.7680.178 is affected. The flaw is confirmed as exploited in the wild: CISA added it to the Known Exploited Vulnerabilities catalog on 2026-04-01, and its EPSS score of 4.9% (92nd percentile) indicates a meaningful near-term exploitation probability.

Do: Update Google Chrome to 146.0.7680.178 or later on all endpoints immediately, prioritizing internet-facing and high-risk user populations given the KEV listing. Because the bug requires a compromised renderer, treat it as part of a chained attack and ensure other browser-layer defenses (renderer sandbox enabled, prompt patching of related renderer bugs) are in place; federal agencies must follow BOD 22-01 remediation timelines or discontinue use if patching is unavailable.

8.85% KEV
  • Google Chrome prior to 146.0.7680.178
  • Google Dawn (WebGPU implementation bundled in Chrome) as shipped in Chrome prior to 146.0.7680.178
masseffectively all Chrome users on unpatched builds
CVE-2026-84352
+1 in the same advisory: …84353
Use-after-free in WebGL in Chrome for Android allows out-of-sandbox code execution

CVE-2026-84352 is a use-after-free memory-safety flaw (CWE-416) in the WebGL component of Google Chrome on Android, rated Critical with a CVSS 3.1 score of 9.6. It is triggered when a remote attacker persuades a user to open a specially crafted HTML page in the vulnerable browser. Successful exploitation lets the attacker execute arbitrary code outside the browser's sandbox, meaning the compromise is not limited to the renderer process and could yield high-impact confidentiality, integrity, and availability loss on the device. Only Chrome on Android prior to version 152.0.7977.75 is affected per the advisory, while desktop Chrome is not listed as impacted. There is currently no known public proof-of-concept, the flaw is not in CISA's KEV catalog, and EPSS estimates only a 0.3% chance of exploitation within 30 days, though it has drawn public coverage warning users about critical Chrome flaws on malicious websites.

Do: Update Chrome for Android via the Play Store to version 152.0.7977.75 or later as soon as it is available, and force-update managed Android fleets via MDM/enterprise Chrome management. Until patched, avoid opening links from untrusted sources in Chrome on Android. Users of other Chromium-based Android browsers should watch for corresponding updates, since the underlying Chromium code is shared.

9.6<1%
  • google chrome (on Android) prior to 152.0.7977.75
mass≈5+ billion installations (Chrome for Android has 5B+ Play Store installs and is the default browser on most Android devices)
CVE-2026-85046
Actively Exploited V8 Type Confusion in Google Chrome (CVE-2026-85046)

Google Chrome versions prior to 152.0.7977.82 contain a type confusion flaw (CWE-843) in the V8 JavaScript engine, which mishandles object types during engine operations (public proof-of-concept writeups indicate it is reachable through array sorting and WebAssembly-related code paths). A remote attacker triggers the flaw simply by getting a user to open a crafted HTML page, with no privileges or authentication required. Successful exploitation lets the attacker execute arbitrary code inside the browser's sandbox, and public reporting shows it being chained with Windows zero-days (the 'BlueMoon' exploit kit) by Chinese espionage groups for broader compromise. Any user of an unpatched Chrome or another build embedding the affected V8 engine is exposed. The vulnerability is a zero-day that was actively exploited in the wild before patching, was added to CISA's KEV on 2026-09-04, and has five public proof-of-concept references.

Do: Update Google Chrome to 152.0.7977.82 or later immediately, and apply the corresponding V8 fix in any Chromium-based browser in use. Federal agencies must apply mitigations in line with CISA BOD 26-04 and its cloud-services requirements, evaluating each asset's internet exposure. Because public reporting shows this flaw chained with Windows zero-days in 'BlueMoon' attacks, patch the related Windows vulnerabilities as well and hunt for signs of exploit-chain activity on high-exposure endpoints.

8.81% KEV PoC ×5
  • Google Chrome prior to 152.0.7977.82
  • Google Chromium V8 V8 engine versions bundled with Chrome prior to 152.0.7977.82
massmultiple billions of users/installs (Chrome is the dominant desktop browser at roughly 65% market share, with an estimated 3+ billion active users, plus…