Google patches an actively exploited Chrome V8 flaw that allows arbitrary code execution inside the sandbox via a crafted HTML page.

Zero-day vulnerability puts billions of web users at risk to hackers

La correzione riguarda CVE-2026-85046, una type confusion nel motore V8 con CVSS 8.8: basta una pagina HTML costruita ad arte per eseguire codice nella sandbox. � il sesto…