Actively Exploited Chromium Sandbox RCE Affects All Major Browsers
A type-confusion vulnerability in V8, tracked as CVE-2026-85046, is being actively exploited in the wild and affects Chromium-based browsers prior to version 152.0.7977.82. A crafted HTML page can let a remote attacker run arbitrary code inside the browser sandbox.
Since Chrome, Edge, Brave, and most other major browsers share the Chromium engine, the flaw exposes billions of users to a credible, actively exploited attack. It highlights the fragility of relying on a single rendering engine across the web and makes urgent patching essential for both consumers and enterprises.
The bug is a type confusion in V8, Chrome's JavaScript and WebAssembly engine, and carries a CVSS score of 8.8 (High). Google fixed it in Chrome 152.0.7977.82 and reportedly paid a $1,000 bug bounty; users should also update Chromium derivatives because many browsers lag upstream releases.
hackernews · negura · · Discussion · Single source
Background, discussion, and references
Market impact
The transmission channel is infrastructure-level: until patched, Chromium-based browsers are a potential entry point for stealing crypto wallet keys, recovery phrases, or DeFi session credentials. No specific asset or venue is directly implicated, so the market effect is indirect and tied to Web3 user security rather than to trading fundamentals.
Background
Browsers use sandboxing to isolate code downloaded from the internet so that a malicious page cannot compromise the rest of the operating system. RCE refers to a vulnerability that lets attackers run their own code on a victim's machine. Type confusion means the engine mistakes one JavaScript object type for another, corrupting memory in an exploitable way. V8 bugs of this kind have historically been among the most common root causes of actively exploited Chrome zero-days; a sandboxed RCE is still serious because it can be paired with a separate sandbox-escape exploit to gain full system access.
Discussion
Commenters debated the economics of the bug, noting that Google paid only $1,000 for an already exploited zero-day, and questioned why another V8 type-confusion got attention when similar bugs appear constantly. Others expressed frustration about the inherent risk of executing JavaScript/WASM from the web, joked about disconnecting entirely, and compared how quickly Brave versus GrapheneOS' Vanadium shipped fixes.
References
Tags
#security#chromium#CVE#RCE#browser