CISA adds actively exploited Chromium V8 type confusion flaw CVE-2026-85046 to KEV catalog; Google patches Chrome 152.0.7977.82
CISA added CVE-2026-85046, a type confusion vulnerability in Google Chromium's V8 engine with evidence of active exploitation, to the Known Exploited Vulnerabilities catalog on September 4, 2026. Google fixed the flaw in Chrome Stable channel version…
On September 4, 2026, CISA added CVE-2026-85046 to its Known Exploited Vulnerabilities (KEV) catalog based on evidence of active exploitation. The flaw is a type confusion vulnerability in Google Chromium's V8 engine; one report (Cyber Security News, 2026-09-08) classifies it as CWE-843 and states that a remote attacker can trigger arbitrary code execution inside the browser sandbox via a specially crafted HTML page, characterizing it as a zero-day. The Canadian Centre for Cyber Security (advisory AV26-883, Update 1) reports that Google fixed CVE-2026-85046 in Chrome 152.0.7977.82 and that an exploit exists in the wild, urging immediate updates to the desktop Chrome stable channel. Google Chrome is directly affected; Microsoft Edge, Opera, and other Chromium-based browsers may also be impacted depending on their bundled V8 version, and users of those browsers must track their respective vendors' updates. Under Binding Operational Directive (BOD) 26-04, Federal Civilian Executive Branch agencies must prioritize remediation of KEV vulnerabilities on exposed assets and check for pre-patch compromise; CISA notes type confusion is a frequent attack vector and urges all organizations to prioritize patching. Enterprises are advised to inventory all Chromium-based browsers, verify updates, and monitor proxy and endpoint telemetry.
- CVE-2026-85046: type confusion vulnerability in Google Chromium's V8 engine; classified as CWE-843 by one source
- Added to the CISA Known Exploited Vulnerabilities catalog on September 4, 2026, based on evidence of active exploitation
- Remote attacker can trigger arbitrary code execution inside the browser sandbox via a specially crafted HTML page (per Cyber Security News)
- Fixed in Google Chrome Stable channel version 152.0.7977.82; Chrome versions prior to 152.0.7977.82 are affected (per Canadian Centre for Cyber Security advisory AV26-883, Update 1)
- Google Chrome is directly affected; Microsoft Edge, Opera, and other Chromium-based browsers may also be impacted depending on their V8 version
- Under BOD 26-04, FCEB agencies must prioritize remediation of KEV vulnerabilities on exposed assets and assess for pre-patch compromise
- Canadian advisory AV26-883 urges immediate patching of the desktop Chrome stable channel
- One source characterizes the flaw as a zero-day; the other two reports do not use that term, but all agree exploitation is active
Coverage timelineoldest first · each row is one article
- · 12d agoCISA Adds One Known Exploited Vulnerability to Catalog
CISA Advisories· 80
CISA added CVE-2026-85046, a Google Chromium V8 type confusion vulnerability with evidence of active exploitation, to its KEV Catalog.
Vulnerabilities in this storyAll →
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2026-85046 | Actively Exploited V8 Type Confusion in Google Chrome (CVE-2026-85046) Google Chrome versions prior to 152.0.7977.82 contain a type confusion flaw (CWE-843) in the V8 JavaScript engine, which mishandles object types during engine operations (public proof-of-concept writeups indicate it is reachable through array sorting and WebAssembly-related code paths). A remote attacker triggers the flaw simply by getting a user to open a crafted HTML page, with no privileges or authentication required. Successful exploitation lets the attacker execute arbitrary code inside the browser's sandbox, and public reporting shows it being chained with Windows zero-days (the 'BlueMoon' exploit kit) by Chinese espionage groups for broader compromise. Any user of an unpatched Chrome or another build embedding the affected V8 engine is exposed. The vulnerability is a zero-day that was actively exploited in the wild before patching, was added to CISA's KEV on 2026-09-04, and has five public proof-of-concept references. Do: Update Google Chrome to 152.0.7977.82 or later immediately, and apply the corresponding V8 fix in any Chromium-based browser in use. Federal agencies must apply mitigations in line with CISA BOD 26-04 and its cloud-services requirements, evaluating each asset's internet exposure. Because public reporting shows this flaw chained with Windows zero-days in 'BlueMoon' attacks, patch the related Windows vulnerabilities as well and hunt for signs of exploit-chain activity on high-exposure endpoints. | 8.8 | 1% | KEV PoC ×5 |
| massmultiple billions of users/installs (Chrome is the dominant desktop browser at roughly 65% market share, with an estimated 3+ billion active users, plus… |