CVE-2026-85046 is a V8 type confusion, rated 8.8, exploited in the wild, and the sixth actively exploited Chrome zero-day of 2026. It was reported on 4 August and awarded $1,000 — an amount that does not appear anywhere on Chrome's published memory-corruption reward schedule. Several explanations fit. Google has offered none.
1 article — 2026-09-07
Authoritative record
Root Notes reports on this identifier; it does not maintain it. For the vendor advisory, the affected versions and the scoring, NVD and MITRE hold the primary records.
CVE-2026-85046 is a V8 type confusion, rated 8.8, exploited in the wild, and the sixth actively exploited Chrome zero-day of 2026. It was reported on 4 August and awarded $1,000 — an amount that does not appear anywhere on Chrome's published memory-corruption reward schedule. Several explanations fit. Google has offered none.