important · Research — Browser
Google says attackers are exploiting a V8 type confusion in Chrome.
Affects
Google Chrome, the web browser on Android and desktop operating systems.
The established path begins when Chrome loads attacker-controlled web content and reaches the V8 type confusion tracked as CVE-2026-85046.
Detail and 3 sources
Google has published a fix. We still do not know what the exploit gains after corruption or whether it requires a separate sandbox escape.
Chain to watch
Deliver attacker-controlled web content to Chrome.→↓Trigger the V8 type confusion tracked as CVE-2026-85046.→↓Google observes exploitation in the wild.→↓The restricted record leaves the resulting memory primitive, renderer control, and any sandbox escape unestablished.
Unverified chainObtain the restricted Chromium bug, an incident artifact, or a working testcase and establish the memory primitive, process control, and escape requirements.