ZeroHour
Cyber Security Newspublished ()ingested Kavichselvan

CISA Warns of Chromium Type Confusion 0-Day Vulnerability Actively Exploited in Attacks

criticalExploit / PoC exploited in the wildimportance 92CVE-2026-85046
AI summary · glm-5.3-flash

CISA added the actively exploited Chromium V8 type confusion zero-day CVE-2026-85046 to its KEV catalog, urging patching of Chrome, Edge, and Opera.

CISA added CVE-2026-85046, a V8 type confusion flaw (CWE-843) in Chromium-based browsers, to its Known Exploited Vulnerabilities catalog. A remote attacker can trigger arbitrary code execution inside the browser sandbox via a specially crafted HTML page. Google Chrome is directly affected, and Microsoft Edge, Opera, and other Chromium-based browsers may also be impacted depending on their V8 version. Google has released a Stable channel Chrome update, and CISA directs mitigations under Binding Operational Directive 26-04.

  • CVE-2026-85046 is a V8 type confusion flaw (CWE-843) enabling arbitrary code execution in the browser sandbox.
  • CISA added it to the KEV catalog, confirming exploitation is observed in real attacks.
  • Google shipped a Stable channel fix; Edge and Opera users must track their vendors' updates.
  • Enterprises should inventory all Chromium browsers, verify updates, and monitor proxy and endpoint telemetry.
OrganizationsCISA

Vulnerabilities mentionedAll →

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2026-85046
Actively Exploited V8 Type Confusion in Google Chrome (CVE-2026-85046)

Google Chrome versions prior to 152.0.7977.82 contain a type confusion flaw (CWE-843) in the V8 JavaScript engine, which mishandles object types during engine operations (public proof-of-concept writeups indicate it is reachable through array sorting and WebAssembly-related code paths). A remote attacker triggers the flaw simply by getting a user to open a crafted HTML page, with no privileges or authentication required. Successful exploitation lets the attacker execute arbitrary code inside the browser's sandbox, and public reporting shows it being chained with Windows zero-days (the 'BlueMoon' exploit kit) by Chinese espionage groups for broader compromise. Any user of an unpatched Chrome or another build embedding the affected V8 engine is exposed. The vulnerability is a zero-day that was actively exploited in the wild before patching, was added to CISA's KEV on 2026-09-04, and has five public proof-of-concept references.

Do: Update Google Chrome to 152.0.7977.82 or later immediately, and apply the corresponding V8 fix in any Chromium-based browser in use. Federal agencies must apply mitigations in line with CISA BOD 26-04 and its cloud-services requirements, evaluating each asset's internet exposure. Because public reporting shows this flaw chained with Windows zero-days in 'BlueMoon' attacks, patch the related Windows vulnerabilities as well and hunt for signs of exploit-chain activity on high-exposure endpoints.

8.81% KEV PoC ×5
  • Google Chrome prior to 152.0.7977.82
  • Google Chromium V8 V8 engine versions bundled with Chrome prior to 152.0.7977.82
massmultiple billions of users/installs (Chrome is the dominant desktop browser at roughly 65% market share, with an estimated 3+ billion active users, plus…
Full article465 words · extracted from cybersecuritynews.com · click to collapse

CISA has added a critical Google Chromium V8 type confusion vulnerability, tracked as CVE-2026-85046, to its Known Exploited Vulnerabilities (KEV) Catalog, warning that the flaw is being actively exploited in attacks.

CVE-2026-85046 affects the V8 JavaScript and WebAssembly engine used by Chromium-based browsers. The vulnerability stems from type confusion, classified under CWE-843, a weakness that occurs when software incorrectly handles an object as though it were a different data type. In a browser engine, this can lead to unexpected memory behavior and potentially provide attackers with a path to execute arbitrary code.

According to the vulnerability description, a remote attacker could exploit CVE-2026-85046 by persuading a target to load a specially crafted HTML page. Successful exploitation may enable arbitrary code execution inside the browser sandbox.

Although browser sandboxing is an important security boundary designed to limit the impact of malicious web content, code execution within that environment can still expose users to credential theft, malicious downloads, surveillance, or follow-on exploitation attempts.

Chromium Type Confusion 0-Day

The issue is particularly significant because Chromium serves as the foundation for several widely deployed browsers. Google Chrome is directly affected, while other Chromium-based products, including Microsoft Edge and Opera, could also be impacted depending on their V8 and Chromium version.

Organizations should not assume that patching Chrome alone addresses their exposure; security teams should inventory all managed browsers and verify available vendor updates for each platform.

CISA’s KEV designation indicates that exploitation is not merely theoretical. The agency did not state whether CVE-2026-85046 has been used in ransomware operations, and the ransomware-campaign field is currently listed as unknown.

Binding Operational Directive 26-04 does not specify a forensic triage requirement, but CISA recommends that organizations apply vendor-recommended mitigations and evaluate the internet exposure of affected assets.

Google has published a Stable Channel update for Chrome desktop users, and administrators should prioritize deployment through enterprise update-management tools.

Security teams should also confirm that automatic browser updates are enabled, identify endpoints running unsupported operating systems or outdated browser builds, and monitor web proxy, endpoint, and browser telemetry for suspicious activity involving newly visited or untrusted domains.

For enterprises, the urgency extends beyond standard patching. Browsers are routinely used to access cloud administration portals, corporate email, source-code repositories, and SaaS platforms, making an actively exploited browser flaw a valuable initial-access opportunity.

Restricting unnecessary browser extensions, enforcing phishing-resistant MFA, and maintaining endpoint detection coverage can reduce the damage if browser-based exploitation occurs.

CISA has instructed stakeholders to apply mitigations consistent with BOD 26-04 risk-based patching guidance or discontinue use of affected products when mitigations are unavailable.

Learn 7 Metric-Gated AI SOC Deployment Phases – Download Free AI SOC Deployment Playbook 2026.

Guru Baranhttps://cybersecuritynews.com

Gurubaran KS is a cybersecurity analyst, and Journalist with a strong focus on emerging threats and digital defense strategies. He is the Co-Founder and Editor-in-Chief of Cyber Security News, where he leads editorial coverage on global cybersecurity developments.

Text extracted automatically; images, tables and formatting may be missing. Original: https://cybersecuritynews.com/chromium-type-confusion-0-day-vulnerability/