
Proof-of-concept trigger for CVE-2026-85045, a Chrome V8 Maglev deoptimization bug causing incorrect array output on vulnerable builds.
A training poc I cooked up while going after the larger chains.
Maglev reuses one mutable HeapNumber while materializing recursive deoptimization frames. The exact upstream trigger produces [0,3,3,3] on both 148 builds and 152.0.7977.75, versus [0,1,2,3] on fixed 152.0.7977.82.
Load poc.js as a page script with --js-flags="--allow-natives-syntax --maglev".