Critical Active Exploitation of Google Chromium V8 Engine Sandbox Escape
Active exploitation of CVE-2026-85046 in the Google Chromium V8 JavaScript engine allows for remote code execution (RCE) and a complete sandbox escape. The vulnerability leverages memory corruption—specifically type confusion or use-after-free flaws—to establish out-of-bounds (OOB) read/write primitives. By bypassing the Chromium multi-process security architecture through manipulated Inter-Process Communication (IPC), attackers can elevate privileges from the restricted renderer process to the host operating system. This critical flaw affects all Chromium-based browsers and has been added to the CISA Known Exploited Vulnerabilities (KEV) catalog. Immediate remediation requires updating to version 149.0.7827.102.103 for Windows/macOS or 149.0.7827.102 for Linux.
-
Vulnerability Mechanics: Memory Corruption
- Exploitation of type confusion or use-after-free flaws within the V8 engine core.
- Establishment of OOB read/write primitives to manipulate process memory.
- Achievement of initial RCE within the restricted renderer process.
-
Attack Vector: Sandbox Escape
- Bypass of Chromium's multi-process isolation via IPC primitives.
- Privilege escalation from the renderer sandbox to the host OS.
- Technical fixes and code path modifications documented in Chromium Issue 405143032.
-
Threat Landscape: Global Active Exploitation
- Confirmed zero-day exploitation in the wild targeting billions of users.
- Universal impact across the Chromium ecosystem, including Chrome, Microsoft Edge, Brave, and Opera.
- CISA KEV designation mandating urgent patching for federal and enterprise networks.
-
Regulatory and Compliance Impact
- Case study for EU Cyber Resilience Act (CRA) regarding rapid patch mandates.
- Increased pressure on vendors to minimize the window between discovery and deployment.
- Heightened compliance risks for organizations lacking emergency update cycles.
-
Detection and Remediation
- Mandatory update to v149.0.7827.102.103 (Windows/macOS) or v149.0.7827.102 (Linux).
- EDR monitoring for anomalous child processes spawned from browser threads (e.g.,
chrome.exespawningcmd.exeorsh). - Implementation of strict site isolation and memory protection policies to limit lateral movement.
Related posts
- blackswan-cybersecurity.com — THREAT ADVISORY Google Chrome Zero-Day (CVE-2026-85046) September 4, 2026
- news4hackers.com — Google Warns of New Chrome Zero-Day Vulnerability Exploited in Cyber Attacks
- news.ycombinator.com — Actively exploited sandbox RCE in all Chromium versions
- threatprotect.qualys.com — Google Chrome Zero-day Vulnerability Exploited in the Wild (CVE-2026-85046)
- techjacksolutions.com — Chrome Zero-Day Under Active Exploitation: Google Pushes Emergency Patch Across 3 Billion Installs
- Cybersecurity News — Hackers Chain Chrome and Windows Zero-Days in New BlueMoon Exploit Kit Attacks
- socprime.com — CVE-2026-87491: Chrome V8 Zero-Day Exploited in the Wild Enables Arbitrary Code Execution
- Malware News — Gemini Hacked Three Companies in First Known Breakout by Google’s AI
- DEV Community — The Gemini breakout verdict has to come from the boundary, not the model's mouth
- forkast.news — When AI Agents Escape Their Sandbox, Who Pays? Europe’s Product Law Wasn’t Built for This
- DEV Community — I Built a Virtual Machine Inside the Xbox Sandbox. Then I Let AI Agents Build on Top of It.
- The Hacker News — Chinese Hackers Exploit Chrome-Windows Zero-Day Chain to Deploy CLEANGULP Malware
- simplysecuregroup.com — Google warns of new Chrome zero-day flaw exploited in attacks
- socprime.com — CVE-2026-85046: Actively Exploited Chrome V8 Zero-Day Enables Code Execution
- penligent.ai — CVE-2026-85046: Chrome V8 Zero-Day Exploited in the Wild
- The Record by Recorded Future — Multiple Chinese hacking groups seen using identical Chrome zero-day exploit
- simplysecuregroup.com — Hackers Chain Chrome and Windows Zero-Days in New BlueMoon Exploit Kit Attacks
- gbhackers.com — China-Linked Hackers Exploit Chrome and Windows Zero-Days in BlueMoon Attacks
- DEV Community — The Gemini breakout is a judge problem, not a jailbreak problem
- Dark Reading — AI Sandbox Escapes: Why Forensic Readiness Matters More Than Containment
- Cybersecurity News — Critical Chrome 0-Day Vulnerability Actively Exploited in the Wild
- thehackernews.com — Google Releases Chrome Update to Patch Actively Exploited V8 Zero-Day
- Malwarebytes
- Securityaffairs
- Cyberinsider
- www.helpnetsecurity.com — Google patches actively exploited Chrome zero-day (CVE-2026-85046)
- eSecurity Planet — Google’s Chrome Update Patches Sixth Zero-Day Exploited in 2026
- Thenextweb
- Bleepingcomputer
- Hothardware
- Securityaffairs
- Menlosecurity
- Issues
- News
- Shattered
- Cybernews
- Forbes
- bleepingcomputer.com — Google warns of new Chrome zero-day bug exploited in attacks
- Independent
- The-independent
- www.helpnetsecurity.com — Google fixes yet another actively exploited Chrome zero-day (CVE-2026-87491)
- thehackernews.com — Chrome V8 Zero-Day Exploited in the Wild Enables Code Execution Inside Sandbox
- thehackernews.com — Four Spy Groups Used the Same Chrome and Windows Exploit Kit Within a Week
- Proofpoint
- Cyberscoop
- SC Media — Chinese state-linked hackers exploit Chrome vulnerability
- Tenable
- Bitdefender
- Volexity
- Security Affairs — Four Nation-State Actors Used the Same Chrome Zero-Day Exploit Kit Within 12 Days
- bleepingcomputer.com — New 'BlueMoon' kit exploited Windows and Chrome zero-day flaws
- Cyberexperts
- Malwarebytes
- Esecurityplanet
- Keysight
- Oodaloop
- News
- Oktacron
- The Hacker News — Google Gemini Broke Into Real Company Systems After Security Test Domain Mix-Up
- Security Affairs — Google Gemini also Broke Out of Its Test Environment
- Timesofindia
- Pluang
- Youtube
- Thenationalnews
- Theguardian
- Timesofisrael
- Calcalistech
- SecurityWeek — Chrome 153 Patches Seventh Zero-Day of 2026