The V8 vulnerability being exploited today, CVE-2026-85046, is listed in NVD under CWE-843, "Access of Resource Using Incompatible Type ('Type Confusion')."[2] On this class of vulnerabilities, MITRE explains:
> When a memory buffer is accessed using the wrong type, it could read or write memory out of the bounds of the buffer
Memory safety is specifically intended to prevent errors like these from becoming arbitrary out-of-bounds memory access and native code execution. Even type safety --- from the 1970s --- can prevent type confusion.
The CISA and the NSA have called for the adoption of memory-safe languages.[3] We exercise poor engineering judgment and poor ethics, as an industry, when we continue to expose users to classes of wholly avoidable security weaknesses in Internet-facing software.
[1] https://en.wikipedia.org/wiki/Heartbleed
[2] https://cwe.mitre.org/data/definitions/843.html
[3] https://www.nsa.gov/Press-Room/Press-Releases-Statements/Pre...