Act
active
Chrome V8 Type Confusion Zero-Day CVE-2026-85046 Actively Exploited
- Engineer — Act: Actively exploited V8 type confusion (CVSS 8.8) with a public PoC on GitHub; update all managed Chrome installations to 152.0.7977.82 immediately and check for pending Chromium-based browser updates (Edge, Brave).
- SOC/IR — Act: Active in-the-wild exploitation means assume-breach posture for unpatched endpoints; hunt for anomalous child processes or shell activity spawned from browser processes since the disclosure date, and monitor web proxy logs for suspicious redirect chains that may indicate exploit delivery.
- Leader — Learn: High-severity browser zero-day under active exploitation, but this is a standard patch-cycle item your engineering team should drive; escalate only if internal compromise indicators surface during the hunt.
- Signals: CVE-2026-85046 — CISA KEV: not listed, EPSS 0.00, public PoC on GitHub
This entry was curated and judged by AI (Claude) with automated enrichment
(CISA KEV / EPSS / public PoC). Verify against the original source before
acting. Found a bad verdict?
Report it —
confirmed errors go to the corrections log.