Security Advisory Desk
unratedQCS priority 70/100Microsoft

CVE-2026-85046: Chromium: CVE-2026-85046 Type confusion in V8

A security flaw called CVE-2026-85046 was found in the V8 JavaScript engine used by Chromium-based browsers, including Microsoft Edge. This flaw involves confusion in how types are handled in memory, which can cause software errors. Google knows this flaw is being exploited by attackers. Microsoft has fixed this issue in a recent Edge update to keep users safe.

Published 8/9/2026, 7:00:00 amVerified 11/9/2026, 3:21:46 amRevision 1
Microsoft unrated network security advisory visual

In plain language

What this advisory means

A security flaw called CVE-2026-85046 was found in the V8 JavaScript engine used by Chromium-based browsers, including Microsoft Edge. This flaw involves confusion in how types are handled in memory, which can cause software errors. Google knows this flaw is being exploited by attackers. Microsoft has fixed this issue in a recent Edge update to keep users safe.

Technical explanation

How the issue affects the environment

CVE-2026-85046 is a type confusion vulnerability in the V8 JavaScript engine within Chromium. Type confusion means that the engine misinterprets the data type of an object, leading to undefined behavior such as memory corruption or arbitrary code execution. This can be exploited by crafted JavaScript to cause a security compromise in the browser. The issue was fixed in Chromium and the fix has been incorporated into Microsoft Edge version 152.0.4191.62.

Operational impact

Why teams should care

If unaddressed, this vulnerability could allow attackers to execute arbitrary code within the context of the browser, potentially leading to data theft, system compromise, or unauthorized access to sensitive information. This impacts organizations using Microsoft Edge, increasing potential risk from targeted attacks or drive-by exploits on web content.

Immediate action

Users and organizations should upgrade Microsoft Edge to version 152.0.4191.62 or later, which contains the patch for this vulnerability as ingested from Chromium upstream.

Affected and fixed releases

Affected versionsConfirm in the official vendor advisory
Fixed versions152.0.4191.62

Temporary risk reduction

The official source does not specify any workaround for this vulnerability aside from applying the update.

Evidence and validation checklist

  • Microsoft Security Response Center advisory confirms CVE-2026-85046 affects Chromium's V8 engine and is addressed in Microsoft Edge update 152.0.4191.62.
  • Google Chrome Releases acknowledge active exploitation in the wild.
  • MSRC Security Update Guide documentation states the fixed version and advises users to update Edge.
  • Advisory notes that Microsoft Edge ingests Chromium fixes and provides instructions to check browser version.

Authoritative reference

Microsoft Security Response Center

QCS detected and normalized this record from the official source. Vendor guidance remains authoritative.

Open source