NPM · SEPTEMBER 2026 · CONFIRMED

V8 npm Package Vulnerability CVE-2026-85046: Active Exploitation

Severity
HIGH
CVSS
8.8
Affected component
v8 (npm)
Affected versions
>= 3.29.86, <= 3.29.86 or >= 3.29.85, <= 3.29.85 or >= 3.29.80, <= 3.29.80 or >= 3.29.79, <= 3.29.79 or >= 3.29.77, <= 3.29.77 or >= 3.29.76, <= 3.29.76 or >= 3.29.73, <= 3.29.73 or >= 3.29.72, <= 3.29.72 or >= 3.29.71, <= 3.29.71 or >= 3.29.69, <= 3.29.69 or >= 3.29.68, <= 3.29.68 or >= 3.29.67, <= 3.29.67 or >= 3.29.65, <= 3.29.65 or >= 3.29.63, <= 3.29.63 or >= 3.29.62, <= 3.29.62 or >= 3.29.61, <= 3.29.61 or >= 3.29.60, <= 3.29.60 or >= 3.29.58, <= 3.29.58 or >= 3.29.56, <= 3.29.56 or >= 3.29.55, <= 3.29.55 or >= 3.29.54, <= 3.29.54 or >= 3.29.52, <= 3.29.52 or >= 3.29.51, <= 3.29.51 or >= 3.29.49, <= 3.29.49 or >= 3.29.48, <= 3.29.48 or >= 3.29.47, <= 3.29.47 or >= 3.29.46, <= 3.29.46 or >= 3.29.45, <= 3.29.45 or >= 3.29.44, <= 3.29.44 or >= 3.29.42, <= 3.29.42 or >= 3.29.39, <= 3.29.39 or >= 3.29.37, <= 3.29.37 or >= 3.29.36, <= 3.29.36 or >= 3.29.34, <= 3.29.34 or >= 3.29.33, <= 3.29.33 or >= 3.29.32, <= 3.29.32 or >= 3.29.31, <= 3.29.31 or >= 3.29.30, <= 3.29.30 or >= 3.29.28, <= 3.29.28 or >= 3.29.26, <= 3.29.26 or >= 3.29.22, <= 3.29.22 or >= 3.29.21, <= 3.29.21 or >= 3.29.19, <= 3.29.19 or >= 3.29.18, <= 3.29.18 or >= 3.29.15, <= 3.29.15 or >= 3.29.13, <= 3.29.13 or >= 3.29.12, <= 3.29.12 or >= 3.29.8, <= 3.29.8 or >= 3.29.7, <= 3.29.7 or >= 3.29.6, <= 3.29.6 or >= 3.29.5, <= 3.29.5 or >= 3.29.4, <= 3.29.4 or >= 3.29.3, <= 3.29.3 or >= 3.29.2, <= 3.29.2 or >= 3.29.1, <= 3.29.1 or >= 3.28.72, <= 3.28.72 or >= 3.28.70, <= 3.28.70 or >= 3.28.68, <= 3.28.68 or >= 3.28.67, <= 3.28.67 or >= 3.28.66, <= 3.28.66 or >= 3.28.63, <= 3.28.63 or >= 3.28.61, <= 3.28.61 or >= 3.28.58, <= 3.28.58 or >= 3.28.56, <= 3.28.56 or >= 3.28.55, <= 3.28.55 or >= 3.28.49, <= 3.28.49 or >= 3.28.47, <= 3.28.47 or >= 3.28.46, <= 3.28.46 or >= 3.28.44, <= 3.28.44 or >= 3.28.42, <= 3.28.42 or >= 3.28.41, <= 3.28.41 or >= 3.28.40, <= 3.28.40 or >= 3.28.39, <= 3.28.39 or >= 3.28.37, <= 3.28.37 or >= 3.28.36, <= 3.28.36 or >= 3.28.34, <= 3.28.34 or >= 3.28.33, <= 3.28.33 or >= 3.26.30, <= 3.26.30 or >= 3.21.18, <= 3.21.18
Patched version
152.0.7977.82
CVE-2026-85046

The V8 npm package, used in Google Chrome, has a high-severity vulnerability tracked as CVE-2026-85046 that is actively being exploited in the wild. This vulnerability is a type confusion bug in Chrome's JavaScript and WebAssembly engine.

What happened

The V8 npm package, which is integral to Google Chrome's JavaScript and WebAssembly engine, has been identified with a critical vulnerability. This vulnerability, designated as CVE-2026-85046, is a type confusion bug that poses a significant risk to systems utilizing affected versions of the package. The exploit has been confirmed to be active in the wild, indicating that malicious actors are already leveraging this flaw to compromise systems.

To assess your exposure, review the version of the V8 npm package in use within your systems. The vulnerability affects a wide range of versions, from 3.29.86 down to 3.21.18, inclusive of all versions listed in the affected components section. It is crucial to verify if your system is running any of these vulnerable versions.

What to do about it

How 0Day would have caught this

MATCHED TO YOUR ACTUAL DEPENDENCY GRAPH0Day matches every incoming threat signal against your GitHub organization’s full dependency graph, including transitive dependencies. If v8 is anywhere in your dependency tree, the engineers who own the affected repositories get a push alert the moment it is flagged — no manual audit to remember to run.

Read how this differs from waiting on a scanner to catch a known advisory, or see the exact, read-only access 0Day needs to do this for an organization.

Frequently asked questions

Am I affected?

You are affected if your system uses the V8 npm package in versions ranging from 3.29.86 down to 3.21.18, inclusive of all versions listed in the affected components section.

What should I do right now?

Upgrade the V8 npm package to version 152.0.7977.82 or later to mitigate the risk of exploitation.

Has this been exploited in the wild?

Yes, the vulnerability has been confirmed to be actively exploited in the wild.

Sources

Join the 0Day waitlist →

← Back to all threats