MALWAREBYTES
Two critical Chrome flaws put users at risk on malicious websites
CRITICAL Chrome use-after-free V8 CVE-2026-85046
Strategic summary
A V8 flaw (CVE-2026-85046) is already being actively exploited in the wild, enabling arbitrary code execution within the Chrome sandbox via crafted HTML pages.
Relevance for you
A V8 flaw (CVE-2026-85046) is already being actively exploited in the wild, enabling arbitrary code execution within the Chrome sandbox via crafted HTML pages.
Risk score
37
- cvss base
- 45.00
- kev bonus
- 0.00
- epss bonus
- 0.00
- poc bonus
- 15.00
- raw before weight
- 60.00
- industry weight
- 1.21
- freshness factor
- 0.50
- exploitability factor
- 1.00
- days old
- 7.00
- vendor mismatch penalty
- 0.00
- consensus penalty
- -3.00
Path: operational
Consensus check
The pipeline self-checks before delivery. These rules lowered the score:
-
TTP_SKIPPEDTTP mapping skipped (placeholder or aggregation article) −3
- Consensus penalty:
- −3.0
- Total penalty:
- −3.0