ZeroHour
Canadian Centre for Cyber Securitypublished ()ingested Canadian Centre for Cyber Security

Google security advisory (AV26-883) – Update 1

highExploit / PoC exploited in the wildimportance 80CVE-2026-85046
AI summary · glm-5.3-flash

Google patched actively exploited Chrome flaw CVE-2026-85046 in Chrome 152.0.7977.82; CISA added it to the KEV catalog, urging updates.

The Canadian Centre for Cyber Security (advisory AV26-883, Update 1) reports Google fixed CVE-2026-85046 in Chrome 152.0.7977.82 and that an exploit exists in the wild. CISA added the vulnerability to its Known Exploited Vulnerabilities database on September 4, 2026. Users and administrators should update Chrome stable desktop channels promptly.

  • CVE-2026-85046 affects Chrome prior to 152.0.7977.82
  • CISA added the flaw to the KEV database on September 4, 2026
  • Advisory AV26-883 urges immediate patching of desktop Chrome

Vulnerabilities mentionedAll →

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2026-85046
Actively Exploited V8 Type Confusion in Google Chrome (CVE-2026-85046)

Google Chrome versions prior to 152.0.7977.82 contain a type confusion flaw (CWE-843) in the V8 JavaScript engine, which mishandles object types during engine operations (public proof-of-concept writeups indicate it is reachable through array sorting and WebAssembly-related code paths). A remote attacker triggers the flaw simply by getting a user to open a crafted HTML page, with no privileges or authentication required. Successful exploitation lets the attacker execute arbitrary code inside the browser's sandbox, and public reporting shows it being chained with Windows zero-days (the 'BlueMoon' exploit kit) by Chinese espionage groups for broader compromise. Any user of an unpatched Chrome or another build embedding the affected V8 engine is exposed. The vulnerability is a zero-day that was actively exploited in the wild before patching, was added to CISA's KEV on 2026-09-04, and has five public proof-of-concept references.

Do: Update Google Chrome to 152.0.7977.82 or later immediately, and apply the corresponding V8 fix in any Chromium-based browser in use. Federal agencies must apply mitigations in line with CISA BOD 26-04 and its cloud-services requirements, evaluating each asset's internet exposure. Because public reporting shows this flaw chained with Windows zero-days in 'BlueMoon' attacks, patch the related Windows vulnerabilities as well and hunt for signs of exploit-chain activity on high-exposure endpoints.

8.81% KEV PoC ×5
  • Google Chrome prior to 152.0.7977.82
  • Google Chromium V8 V8 engine versions bundled with Chrome prior to 152.0.7977.82
massmultiple billions of users/installs (Chrome is the dominant desktop browser at roughly 65% market share, with an estimated 3+ billion active users, plus…
Full article88 words · extracted from cyber.gc.ca · click to collapse

Serial Number: AV26-883
Date: September 4, 2026

As of September 3, 2026, Google is affected by vulnerabilities in the following product:

  • Chrome
    • Prior to 152.0.7977.82

Google is aware that an exploit for CVE-2026-85046 exists in the wild.

Update 1

On September 4, 2026, Cybersecurity and Infrastructure Security Agency (CISA) added CVE-2026-85046 to their Known Exploited Vulnerabilities (KEV) Database.

The Cyber Centre encourages users and administrators to review the provided web links and apply any necessary updates as they become available.

Text extracted automatically; images, tables and formatting may be missing. Original: https://cyber.gc.ca/en/alerts-advisories/google-security-advisory-av26-883