Skip to finding
important · Research — Browser

Google says attackers are exploiting a V8 type confusion in Chrome.

Affects

Google Chrome, the web browser on Android and desktop operating systems.

The established path begins when Chrome loads attacker-controlled web content and reaches the V8 type confusion tracked as CVE-2026-85046.

Detail and 3 sources

Google has published a fix. We still do not know what the exploit gains after corruption or whether it requires a separate sandbox escape.

Chain to watch
Deliver attacker-controlled web content to Chrome.→↓Trigger the V8 type confusion tracked as CVE-2026-85046.→↓Google observes exploitation in the wild.→↓The restricted record leaves the resulting memory primitive, renderer control, and any sandbox escape unestablished.
Unverified chainObtain the restricted Chromium bug, an incident artifact, or a working testcase and establish the memory primitive, process control, and escape requirements.
Share this finding
Get it by email

The same brief, every morning. One email a day, nothing else.

Every finding here carries a source that was checked before it published. If something is wrong, write to admin@fullchain.sh — corrections are published on the day they affect.

Saturday, September 5, 2026