Google Chrome V8 Type Confusion Zero-Day, Actively Exploited

Release Date: 4th September 2026 (Added 8th September 2026)

Impact : CRITICAL

TLP Rating: Clear

The Department of Communications and Digital Transformation (DCDT) through CERT Vanuatu (CERTVU), provides the following advisory.

This alert is relevant to Organizations, System/Network administrators, and all general users of Google Chrome or Chromium-based browsers (including Microsoft Edge, Brave, and Opera, which regularly incorporate the same V8 engine fixes). This alert is intended to be understood by both technical users and systems administrators, and by general staff who simply browse the web.

What is it?

CVE-2026-85046 is a type confusion vulnerability in V8, the JavaScript and WebAssembly engine at the core of Google Chrome, which Google has confirmed is being actively exploited in the wild. The flaw allows a remote attacker to execute arbitrary code inside Chrome’s sandboxed renderer process simply by getting a victim to visit a specially crafted HTML page - no download, login, or file execution is required. CERTVU notes those companion fixes for completeness, but these advisory addresses CVE-2026-85046 specifically, since it is the one confirmed to be under active exploitation.

Reference

  1. https://www.cve.org/CVERecord?id=CVE-2026-85046
  2. https://chromereleases.googleblog.com/2026/09/stable-channel-update-for-desktop_01882797386.html