{
  "schemaVersion": "guard-threat-campaign/v1",
  "id": "HGTC-2026-EBA27319",
  "slug": "cve-2026-85046-chrome-v8-type-confusion-in-the-wild",
  "title": "Chrome V8 type confusion exploited in the wild",
  "aliases": [
    "CVE-2026-85046",
    "Chrome V8 type confusion"
  ],
  "summary": "Google reports a Chrome V8 type-confusion vulnerability (CVE-2026-85046) as exploited in the wild. CISA KEV listed. Upgrade Chrome to the patched stable build (152.0.7977.82 or matching channel).",
  "status": "published",
  "severity": "critical",
  "confidence": "high",
  "uncertainty": "Confirm the exact patched build for your Chrome channel/OS.",
  "firstObservedAt": "2026-09-03T00:00:00.000Z",
  "lastObservedAt": "2026-09-03T12:00:00.000Z",
  "publishedAt": "2026-09-20T19:38:13.035Z",
  "reviewedAt": "2026-09-20T19:37:58.883Z",
  "expiresAt": "2026-09-03T12:00:00.000Z",
  "reviewer": "HOL Guard Security Publishing",
  "sources": [
    {
      "id": "chrome",
      "label": "Chrome stable channel update",
      "url": "https://chromereleases.googleblog.com/2026/09/stable-channel-update-for-desktop_01882797386.html",
      "sourceType": "vendor_advisory",
      "observedAt": "2026-09-03T12:00:00.000Z"
    },
    {
      "id": "cisa-kev",
      "label": "CISA KEV catalog entry",
      "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-85046",
      "sourceType": "government",
      "observedAt": "2026-09-03T12:00:00.000Z"
    },
    {
      "id": "nvd",
      "label": "NVD CVE-2026-85046",
      "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-85046",
      "sourceType": "vulnerability_database",
      "observedAt": "2026-09-03T12:00:00.000Z"
    },
    {
      "id": "hol-blog",
      "label": "HOL Guard operator write-up",
      "url": "https://hol.org/blog/cve-2026-85046-chrome-v8-type-confusion-in-the-wild",
      "sourceType": "other_primary",
      "observedAt": "2026-09-03T12:00:00.000Z"
    }
  ],
  "artifacts": [
    {
      "id": "chrome",
      "artifactClass": "package",
      "ecosystem": "google",
      "name": "Google Chrome",
      "version": "before 152.0.7977.82",
      "defanged": false
    }
  ],
  "indicators": [],
  "timeline": [
    {
      "id": "disclosure",
      "occurredAt": "2026-09-03T00:00:00.000Z",
      "eventType": "disclosure",
      "summary": "Chrome/V8 CVE-2026-85046 type confusion disclosed with in-the-wild exploitation.",
      "sourceIds": [
        "chrome",
        "nvd"
      ]
    },
    {
      "id": "kev",
      "occurredAt": "2026-09-03T00:00:00.000Z",
      "eventType": "other",
      "summary": "CISA listed CVE-2026-85046 in KEV.",
      "sourceIds": [
        "cisa-kev"
      ]
    },
    {
      "id": "hol-publish",
      "occurredAt": "2026-09-03T12:00:00.000Z",
      "eventType": "other",
      "summary": "HOL Guard published operator coverage for CVE-2026-85046.",
      "sourceIds": [
        "hol-blog"
      ]
    }
  ],
  "coverage": [],
  "policies": [],
  "limitations": [
    "Browser update path varies by OS/channel.",
    "CISA KEV elevates urgency.",
    "HOL blog is operator guidance."
  ],
  "correctionHref": "/guard/security/campaigns/cve-2026-85046-chrome-v8-type-confusion-in-the-wild/corrections"
}
