Actively exploited sandbox RCE in all Chromium versions
CVE-2026-85046 is a type confusion vulnerability in V8, the JavaScript engine of Chromium, affecting Google Chrome prior to version 152.0.7977.82. A remote attacker can exploit a crafted HTML page to execute arbitrary code inside the sandbox, with a CVSS score of 8.8 (High). The vulnerability is listed in CISA's Known Exploited Vulnerabilities Catalog, with a required action to apply vendor mitigations by September 18, 2026.
Type confusion in V8 in Google Chrome prior to 152.0.7977.82 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page.
- david_shaw
Let's take a moment to talk about the monetary value of this vulnerability.
According to the Chrome release page (https://chromereleases.googleblog.com/2026/09/stable-channel...), Google paid a researcher $1000 for ethically reporting this.
The CVE associated with it (CVE-2026-85046) is already being exploited in the wild. If we put our thinking caps on, how much do you think this vulnerability is actually worth? How much do you think an organization like Google would spend on, for example, AI tokens or compute to detect this internally before it was found and exploited in the wild?
Ethical disclosure is a complicated topic, because researchers shouldn't hold bugs for ransom or demand high payment. But at the same time, if someone submits a critical issue like this, it makes sense to pay them what the bug's actually worth. Why should a researcher be effectively penalized for responsibly telling a vendor instead of selling the bug to a "research firm" or three-letter agency?
It's one thing if you're an open source project maintainer just trying to put something out to the community. The math is a lot different if you're Google.
- claiir
Aren’t all the big chrome vulnerabilities type confusion?
- publlus_enigma
Normalising running arbitrary code delivered over the internet (in the form of JavaScript and WASM), as a necessary condition for accessing most web pages may not have been one of the best decisions we have made.
- ruuda
> Type confusion in V8
Fortunately I disabled js by default. Unfortunately, it breaks about 30% of the web. Including nvd.nist.gov, which shows a completely blank page without js enabled, even though with js it’s just a simple page with only static content.
- throwatdem12311
I’m so tired. I think I’m just going to get a job as a garbage man and cancel my internet.
- Cider9986
Brave is beating GrapheneOS on update timeliness:
https://github.com/GrapheneOS/Vanadium/releases
https://github.com/brave/brave-browser/releases
Only if you use Nightly wait maybe not.
- neuroticnews25
I would guess it's now trivial for attackers to have an llm analyse every new commit to chromium repo linking to an issue that's 403 for security reasons, but maybe I'm missing something.
- throwaway27448
Hell yea. Let's see some real leaks.
- no-name-here
Is the HN title true that it affects all "all Chromium versions"?
Per OP link, it only affects Chrome versions prior to .82; .82 was released as stable 2 days ago. [1]
(HN title also does not match the original title, which is the CVE ID -- not particularly intuitive.)
[1] https://chromereleases.googleblog.com/2026/09/stable-channel...
- snorbleck
So basically, Edge, Brave and any other browser built on Chromium. Nice.