CVE-2026-85046

Source
https://cve.org/CVERecord?id=CVE-2026-85046
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-85046.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-85046
Downstream
Related
Published
2026-09-03T19:26:12Z
Modified
2026-09-10T08:14:35Z
Severity
  • 8.8 (High) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H CVSS Calculator
Summary
[none]
Details

Type confusion in V8 in Google Chrome prior to 152.0.7977.82 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: High)

Database specific
{
    "cna_assigner": "Chrome",
    "cwe_ids": [
        "CWE-843"
    ],
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/85xxx/CVE-2026-85046.json",
    "unresolved_ranges": [
        {
            "extracted_events": [
                {
                    "introduced": "152.0.7977.82"
                },
                {
                    "last_affected": "152.0.7977.82"
                }
            ],
            "source": "AFFECTED_FIELD"
        }
    ]
}
References

Affected packages

Git / github.com/v8/v8

Affected ranges

Type
GIT
Repo
https://github.com/v8/v8
Events
Introduced
0 Unknown introduced commit / All previous commits are affected
Fixed
Fixed
Database specific
Show details
{
    "cpe": "cpe:2.3:a:google:v8:*:*:*:*:*:*:*:*",
    "extracted_events": [
        {
            "introduced": "0"
        },
        {
            "fixed": "15.3.48"
        }
    ],
    "source": [
        "CPE_RANGE",
        "REFERENCES"
    ]
}

Affected versions

3.*
3.21.18
3.26.30
3.28.33
3.28.34
3.28.36
3.28.37
3.28.39
3.28.40
3.28.41
3.28.42
3.28.44
3.28.46
3.28.47
3.28.49
3.28.55
3.28.56
3.28.58
3.28.61
3.28.63
3.28.66
3.28.67
3.28.68
3.28.70
3.28.72
3.29.1
3.29.12
3.29.13
3.29.15
3.29.18
3.29.19
3.29.2
3.29.21
3.29.22
3.29.26
3.29.28
3.29.3
3.29.30
3.29.31
3.29.32
3.29.33
3.29.34
3.29.36
3.29.37
3.29.39
3.29.4
3.29.42
3.29.44
3.29.45
3.29.46
3.29.47
3.29.48
3.29.49
3.29.5
3.29.51
3.29.52
3.29.54
3.29.55
3.29.56
3.29.58
3.29.6
3.29.60
3.29.61
3.29.62
3.29.63
3.29.65
3.29.67
3.29.68
3.29.69
3.29.7
3.29.71
3.29.72
3.29.73
3.29.76
3.29.77
3.29.79
3.29.8
3.29.80
3.29.85
3.29.86

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-85046.json"
vanir_signatures
[
    {
        "deprecated": false,
        "digest": {
            "function_hash": "45358207864630188459344293886483910446",
            "length": 1081
        },
        "id": "CVE-2026-85046-38d39c92",
        "signature_type": "Function",
        "signature_version": "v1",
        "source": "https://github.com/v8/v8/commit/e0562d87ad9c17042b581582c99237d798572e67",
        "target": {
            "file": "src/compiler/js-call-reducer.cc",
            "function": "JSCallReducer::ReduceArraySort"
        }
    },
    {
        "deprecated": false,
        "digest": {
            "function_hash": "222558120789672035064124608174897430995",
            "length": 7705
        },
        "id": "CVE-2026-85046-735d9c62",
        "signature_type": "Function",
        "signature_version": "v1",
        "source": "https://github.com/v8/v8/commit/e0562d87ad9c17042b581582c99237d798572e67",
        "target": {
            "file": "src/maglev/maglev-graph-builder.cc",
            "function": "MaglevGraphBuilder::TryReduceArrayPrototypeSort"
        }
    },
    {
        "deprecated": false,
        "digest": {
            "line_hashes": [
                "276237460377251467554624861738714942768",
                "149109487908568230797545268525174830315",
                "154524572205460864053538101538965402798"
            ],
            "threshold": 0.9
        },
        "id": "CVE-2026-85046-b587b98a",
        "signature_type": "Line",
        "signature_version": "v1",
        "source": "https://github.com/v8/v8/commit/e0562d87ad9c17042b581582c99237d798572e67",
        "target": {
            "file": "src/maglev/maglev-graph-builder.cc"
        }
    },
    {
        "deprecated": false,
        "digest": {
            "line_hashes": [
                "114195911289116064659621204503232424900",
                "275539454546441511554477030910477724364",
                "185670226296934983802849637816064709447",
                "99708335912348204009061533641606218564",
                "293076281976058452502482822370776412950",
                "265465019099834915682909100150595175239",
                "230001941606322915764733226784461106183",
                "1479274665992495356999278457845978133",
                "27738104712803457571578569672602062953",
                "192958108746716069735488501155478949811",
                "3073859365462618699618322525902668577",
                "50314290904378642910831694373491851784",
                "176973962364254008333876263126268259602"
            ],
            "threshold": 0.9
        },
        "id": "CVE-2026-85046-b79df92a",
        "signature_type": "Line",
        "signature_version": "v1",
        "source": "https://github.com/v8/v8/commit/e0562d87ad9c17042b581582c99237d798572e67",
        "target": {
            "file": "src/compiler/js-call-reducer.cc"
        }
    }
]
vanir_signatures_modified
"2026-09-10T08:14:35Z"