CuraSec

Act active

Chrome V8 Type Confusion Zero-Day CVE-2026-85046 Actively Exploited

2026-09-04 14:56 UTC · The Hacker News · read the source ↗ #browser-security#zero-day#active-exploitation
  • Engineer — Act: Actively exploited V8 type confusion (CVSS 8.8) with a public PoC on GitHub; update all managed Chrome installations to 152.0.7977.82 immediately and check for pending Chromium-based browser updates (Edge, Brave).
  • SOC/IR — Act: Active in-the-wild exploitation means assume-breach posture for unpatched endpoints; hunt for anomalous child processes or shell activity spawned from browser processes since the disclosure date, and monitor web proxy logs for suspicious redirect chains that may indicate exploit delivery.
  • Leader — Learn: High-severity browser zero-day under active exploitation, but this is a standard patch-cycle item your engineering team should drive; escalate only if internal compromise indicators surface during the hunt.
  • Signals: CVE-2026-85046 — CISA KEV: not listed, EPSS 0.00, public PoC on GitHub
This entry was curated and judged by AI (Claude) with automated enrichment (CISA KEV / EPSS / public PoC). Verify against the original source before acting. Found a bad verdict? Report it — confirmed errors go to the corrections log.