News Room
16
Share
Google Patches Actively Exploited Chrome V8 Zero-Day CVE-2026-85046 as CISA Mandates Remediation
highZero-Day Exploits

Google Patches Actively Exploited Chrome V8 Zero-Day CVE-2026-85046 as CISA Mandates Remediation

Google released emergency patches for CVE-2026-85046, a high-severity type confusion zero-day in Chrome's V8 engine exploited in the wild, prompting swift CISA KEV catalog inclusion.

05 September 2026Last updated 05 September 20263 min readGoogle Threat Intelligence Group
E
Encrygma AI Cyber Weapons Advisory Services :We provide AI Cyber Warfare Technologies Reports, including full technical blueprints, tech source codes, entire know how. Consult with us. Click Here

Executive Takeaway — TL;DR

Category:
Zero-Day Exploits
Severity:
High
Actor Type:
APT
Geography:
Global
Confidence:
Confirmed
CVE:
CVE-2026-85046
Source:
Google Threat Intelligence Group
Read Time:
3 min

Executive Summary

On September 4–5, 2026, Google published urgent security updates across Windows, macOS, and Linux platforms to address CVE-2026-85046, an actively exploited zero-day vulnerability residing in Chrome’s V8 JavaScript and WebAssembly engine. The high-severity flaw enables remote attackers to execute arbitrary code within the browser renderer sandbox via crafted web content. Concurrently, the U.S. Cybersecurity and Infrastructure Security Agency (CISA) added the vulnerability to its Known Exploited Vulnerabilities (KEV) catalog, requiring immediate operational intervention across government and commercial enterprises.

Threat Analysis

CVE-2026-85046 marks the sixth zero-day vulnerability patched in Google Chrome in 2026, underscoring intense adversary focus on browser exploitation vectors. Active exploitation in the wild suggests deployment in highly targeted espionage campaigns or commercial spyware operations. Vulnerabilities within V8 remain prime targets for state-sponsored and advanced cybercriminal groups due to the low-interaction requirements; victims need only navigate to an adversary-controlled landing page or view a poisoned advertisement to trigger exploitation.

Technical Details

Tracked with a CVSS score of 8.8, CVE-2026-85046 is classified as a compiler-level type confusion bug in V8. Discovered and reported by independent researcher Salvatore Gulizia (Serotav), the flaw stems from a flaw during JIT compiler optimization where an array containing PACKED_ELEMENTS receives a PACKED_SMI_ELEMENTS map. This type mismatch facilitates arbitrary read and write primitives on the JavaScript heap, allowing an attacker to bypass internal memory protections and achieve remote code execution inside the renderer sandbox. Chaining this flaw with an operating system kernel privilege escalation or sandbox escape yields full host takeover.

Attribution Assessment

Google and threat intelligence authorities have withheld specific intrusion details and tactical telemetry to facilitate enterprise mitigation before broad weaponization occurs. However, the operational pattern aligns closely with advanced persistent threat (APT) groups and commercial surveillance vendors known for stockpiling browser zero-days. Historically, similar V8 JIT zero-days have been weaponized by state-sponsored actors across North America, Europe, and the Middle East.

Implications

Because the underlying V8 architecture powers multiple cross-platform applications, exposure extends past Chrome to other Chromium-based web browsers, including Microsoft Edge, Brave, Opera, and Vivaldi. Unpatched enterprise environments risk widespread client-side compromise, endpoint pivoting, and network credential theft.

Recommendations

  • Immediately update Google Chrome to versions 152.0.7977.82/.83 for Windows/macOS and 152.0.7977.82 for Linux.
  • Monitor downstream advisories and expedite updates for all Chromium-based enterprise browsers.
  • Implement strict endpoint detection rules flagging anomalous child processes spawning from browser binaries.
Professional Spy Phones — ZERO-CLICK Spyware: Samsung Galaxy and iPhone hardware-modified with a dedicated implant for remote surveillance, lawful interception, and corporate compliance monitoring.
ENCRYGMA

Need Zero Click Spyware for Android and iOS?

Encrygma delivers serverless, offline, quantum-safe encrypted communications built for executives, agencies, and operators facing zero-click spyware and advanced mobile surveillance threats.

Request a demo