← Back to Daily Briefing (#Chromium)

Critical Active Exploitation of Google Chromium V8 Engine Sandbox Escape

Published September 5, 2026

Active exploitation of CVE-2026-85046 in the Google Chromium V8 JavaScript engine allows for remote code execution (RCE) and a complete sandbox escape. The vulnerability leverages memory corruption—specifically type confusion or use-after-free flaws—to establish out-of-bounds (OOB) read/write primitives. By bypassing the Chromium multi-process security architecture through manipulated Inter-Process Communication (IPC), attackers can elevate privileges from the restricted renderer process to the host operating system. This critical flaw affects all Chromium-based browsers and has been added to the CISA Known Exploited Vulnerabilities (KEV) catalog. Immediate remediation requires updating to version 149.0.7827.102.103 for Windows/macOS or 149.0.7827.102 for Linux.

  • Vulnerability Mechanics: Memory Corruption

    • Exploitation of type confusion or use-after-free flaws within the V8 engine core.
    • Establishment of OOB read/write primitives to manipulate process memory.
    • Achievement of initial RCE within the restricted renderer process.
  • Attack Vector: Sandbox Escape

    • Bypass of Chromium's multi-process isolation via IPC primitives.
    • Privilege escalation from the renderer sandbox to the host OS.
    • Technical fixes and code path modifications documented in Chromium Issue 405143032.
  • Threat Landscape: Global Active Exploitation

    • Confirmed zero-day exploitation in the wild targeting billions of users.
    • Universal impact across the Chromium ecosystem, including Chrome, Microsoft Edge, Brave, and Opera.
    • CISA KEV designation mandating urgent patching for federal and enterprise networks.
  • Regulatory and Compliance Impact

    • Case study for EU Cyber Resilience Act (CRA) regarding rapid patch mandates.
    • Increased pressure on vendors to minimize the window between discovery and deployment.
    • Heightened compliance risks for organizations lacking emergency update cycles.
  • Detection and Remediation

    • Mandatory update to v149.0.7827.102.103 (Windows/macOS) or v149.0.7827.102 (Linux).
    • EDR monitoring for anomalous child processes spawned from browser threads (e.g., chrome.exe spawning cmd.exe or sh).
    • Implementation of strict site isolation and memory protection policies to limit lateral movement.

Related posts

  1. blackswan-cybersecurity.com — THREAT ADVISORY Google Chrome Zero-Day (CVE-2026-85046) September 4, 2026
  2. news4hackers.com — Google Warns of New Chrome Zero-Day Vulnerability Exploited in Cyber Attacks
  3. news.ycombinator.com — Actively exploited sandbox RCE in all Chromium versions
  4. threatprotect.qualys.com — Google Chrome Zero-day Vulnerability Exploited in the Wild (CVE-2026-85046)
  5. techjacksolutions.com — Chrome Zero-Day Under Active Exploitation: Google Pushes Emergency Patch Across 3 Billion Installs
  6. Cybersecurity News — Hackers Chain Chrome and Windows Zero-Days in New BlueMoon Exploit Kit Attacks
  7. socprime.com — CVE-2026-87491: Chrome V8 Zero-Day Exploited in the Wild Enables Arbitrary Code Execution
  8. Malware News — Gemini Hacked Three Companies in First Known Breakout by Google’s AI
  9. DEV Community — The Gemini breakout verdict has to come from the boundary, not the model's mouth
  10. forkast.news — When AI Agents Escape Their Sandbox, Who Pays? Europe’s Product Law Wasn’t Built for This
  11. DEV Community — I Built a Virtual Machine Inside the Xbox Sandbox. Then I Let AI Agents Build on Top of It.
  12. The Hacker News — Chinese Hackers Exploit Chrome-Windows Zero-Day Chain to Deploy CLEANGULP Malware
  13. simplysecuregroup.com — Google warns of new Chrome zero-day flaw exploited in attacks
  14. socprime.com — CVE-2026-85046: Actively Exploited Chrome V8 Zero-Day Enables Code Execution
  15. penligent.ai — CVE-2026-85046: Chrome V8 Zero-Day Exploited in the Wild
  16. The Record by Recorded Future — Multiple Chinese hacking groups seen using identical Chrome zero-day exploit
  17. simplysecuregroup.com — Hackers Chain Chrome and Windows Zero-Days in New BlueMoon Exploit Kit Attacks
  18. gbhackers.com — China-Linked Hackers Exploit Chrome and Windows Zero-Days in BlueMoon Attacks
  19. DEV Community — The Gemini breakout is a judge problem, not a jailbreak problem
  20. Dark Reading — AI Sandbox Escapes: Why Forensic Readiness Matters More Than Containment
  21. Cybersecurity News — Critical Chrome 0-Day Vulnerability Actively Exploited in the Wild
  22. thehackernews.com — Google Releases Chrome Update to Patch Actively Exploited V8 Zero-Day
  23. Malwarebytes
  24. Securityaffairs
  25. Cyberinsider
  26. www.helpnetsecurity.com — Google patches actively exploited Chrome zero-day (CVE-2026-85046)
  27. eSecurity Planet — Google’s Chrome Update Patches Sixth Zero-Day Exploited in 2026
  28. Thenextweb
  29. Bleepingcomputer
  30. Hothardware
  31. Securityaffairs
  32. Menlosecurity
  33. Issues
  34. News
  35. Shattered
  36. Cybernews
  37. Forbes
  38. bleepingcomputer.com — Google warns of new Chrome zero-day bug exploited in attacks
  39. Reddit
  40. Independent
  41. The-independent
  42. www.helpnetsecurity.com — Google fixes yet another actively exploited Chrome zero-day (CVE-2026-87491)
  43. thehackernews.com — Chrome V8 Zero-Day Exploited in the Wild Enables Code Execution Inside Sandbox
  44. thehackernews.com — Four Spy Groups Used the Same Chrome and Windows Exploit Kit Within a Week
  45. Proofpoint
  46. Cyberscoop
  47. SC Media — Chinese state-linked hackers exploit Chrome vulnerability
  48. Tenable
  49. Bitdefender
  50. Volexity
  51. Security Affairs — Four Nation-State Actors Used the Same Chrome Zero-Day Exploit Kit Within 12 Days
  52. bleepingcomputer.com — New 'BlueMoon' kit exploited Windows and Chrome zero-day flaws
  53. Cyberexperts
  54. Malwarebytes
  55. Esecurityplanet
  56. Keysight
  57. Oodaloop
  58. News
  59. Oktacron
  60. The Hacker News — Google Gemini Broke Into Real Company Systems After Security Test Domain Mix-Up
  61. Security Affairs — Google Gemini also Broke Out of Its Test Environment
  62. Timesofindia
  63. Pluang
  64. Youtube
  65. Thenationalnews
  66. Theguardian
  67. Timesofisrael
  68. Reddit
  69. Calcalistech
  70. SecurityWeek — Chrome 153 Patches Seventh Zero-Day of 2026

LINK COPIED TO CLIPBOARD