{"id":"CVE-2026-85046","details":"Type confusion in V8 in Google Chrome prior to 152.0.7977.82 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: High)","modified":"2026-09-10T08:14:35.525132Z","published":"2026-09-03T19:26:12.609Z","related":["openSUSE-SU-2026:11714-1","openSUSE-SU-2026:21799-1"],"database_specific":{"cna_assigner":"Chrome","cwe_ids":["CWE-843"],"osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/85xxx/CVE-2026-85046.json","unresolved_ranges":[{"extracted_events":[{"introduced":"152.0.7977.82"},{"last_affected":"152.0.7977.82"}],"source":"AFFECTED_FIELD"}]},"references":[{"type":"WEB","url":"https://github.com/Serotav/Writeups/blob/77556c57999805fa7815a114da51d91cf24fbea9/v8/When_Sorting_Leads_To_Confusion.md"},{"type":"WEB","url":"https://issues.chromium.org/issues/542403045"},{"type":"WEB","url":"https://news.ycombinator.com/item?id=49570669"},{"type":"WEB","url":"https://serotav.github.io/Writeups/v8/when-sorting-leads-to-confusion/"},{"type":"WEB","url":"https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-85046"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/85xxx/CVE-2026-85046.json"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-85046"},{"type":"FIX","url":"https://github.com/v8/v8/commit/e0562d87ad9c17042b581582c99237d798572e67"},{"type":"ARTICLE","url":"https://chromereleases.googleblog.com/2026/09/stable-channel-update-for-desktop_01882797386.html"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/v8/v8","events":[{"introduced":"0"},{"fixed":"5a7a80437c7c6c22799b1d6cc287021c3a949a6a"},{"fixed":"e0562d87ad9c17042b581582c99237d798572e67"}],"database_specific":{"cpe":"cpe:2.3:a:google:v8:*:*:*:*:*:*:*:*","extracted_events":[{"introduced":"0"},{"fixed":"15.3.48"}],"source":["CPE_RANGE","REFERENCES"]}}],"versions":["3.29.86","3.29.85","3.29.80","3.29.79","3.29.77","3.29.76","3.29.73","3.29.72","3.29.71","3.29.69","3.29.68","3.29.67","3.29.65","3.29.63","3.29.62","3.29.61","3.29.60","3.29.58","3.29.56","3.29.55","3.29.54","3.29.52","3.29.51","3.29.49","3.29.48","3.29.47","3.29.46","3.29.45","3.29.44","3.29.42","3.29.39","3.29.37","3.29.36","3.29.34","3.29.33","3.29.32","3.29.31","3.29.30","3.29.28","3.29.26","3.29.22","3.29.21","3.29.19","3.29.18","3.29.15","3.29.13","3.29.12","3.29.8","3.29.7","3.29.6","3.29.5","3.29.4","3.29.3","3.29.2","3.29.1","3.28.72","3.28.70","3.28.68","3.28.67","3.28.66","3.28.63","3.28.61","3.28.58","3.28.56","3.28.55","3.28.49","3.28.47","3.28.46","3.28.44","3.28.42","3.28.41","3.28.40","3.28.39","3.28.37","3.28.36","3.28.34","3.28.33","3.26.30","3.21.18"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-85046.json","vanir_signatures_modified":"2026-09-10T08:14:35Z","vanir_signatures":[{"deprecated":false,"digest":{"function_hash":"45358207864630188459344293886483910446","length":1081},"id":"CVE-2026-85046-38d39c92","signature_type":"Function","signature_version":"v1","source":"https://github.com/v8/v8/commit/e0562d87ad9c17042b581582c99237d798572e67","target":{"function":"JSCallReducer::ReduceArraySort","file":"src/compiler/js-call-reducer.cc"}},{"signature_type":"Function","signature_version":"v1","source":"https://github.com/v8/v8/commit/e0562d87ad9c17042b581582c99237d798572e67","target":{"file":"src/maglev/maglev-graph-builder.cc","function":"MaglevGraphBuilder::TryReduceArrayPrototypeSort"},"deprecated":false,"digest":{"length":7705,"function_hash":"222558120789672035064124608174897430995"},"id":"CVE-2026-85046-735d9c62"},{"signature_type":"Line","signature_version":"v1","source":"https://github.com/v8/v8/commit/e0562d87ad9c17042b581582c99237d798572e67","target":{"file":"src/maglev/maglev-graph-builder.cc"},"deprecated":false,"digest":{"line_hashes":["276237460377251467554624861738714942768","149109487908568230797545268525174830315","154524572205460864053538101538965402798"],"threshold":0.9},"id":"CVE-2026-85046-b587b98a"},{"signature_version":"v1","source":"https://github.com/v8/v8/commit/e0562d87ad9c17042b581582c99237d798572e67","target":{"file":"src/compiler/js-call-reducer.cc"},"deprecated":false,"digest":{"line_hashes":["114195911289116064659621204503232424900","275539454546441511554477030910477724364","185670226296934983802849637816064709447","99708335912348204009061533641606218564","293076281976058452502482822370776412950","265465019099834915682909100150595175239","230001941606322915764733226784461106183","1479274665992495356999278457845978133","27738104712803457571578569672602062953","192958108746716069735488501155478949811","3073859365462618699618322525902668577","50314290904378642910831694373491851784","176973962364254008333876263126268259602"],"threshold":0.9},"id":"CVE-2026-85046-b79df92a","signature_type":"Line"}]}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H"}]}