CISA adds actively exploited Chromium V8 type confusion flaw CVE-2026-85046; Chrome fixed in 152.0.7977.82
CISA added Chromium V8 type confusion vulnerability CVE-2026-85046 to the KEV catalog on 2026-09-04 after evidence of active exploitation. Google fixed Chrome in 152.0.7977.82, and federal mitigation is due 2026-09-18 under BOD 26-04.
CISA added CVE-2026-85046, a type confusion vulnerability in Google Chromium's V8 JavaScript engine, to the Known Exploited Vulnerabilities catalog on 2026-09-04 based on evidence of active exploitation. The flaw can allow a remote attacker to execute arbitrary code inside the browser sandbox through a crafted HTML page; Cyber Security News categorizes it as CWE-843 and calls it a zero-day. CISA describes affected software as Chromium-based browsers including Google Chrome, Microsoft Edge, and Opera, while Cyber Security News says Chrome is directly affected and Edge, Opera, and other Chromium-based browsers may also be impacted depending on their V8 version. The Canadian Centre for Cyber Security reports Google fixed the flaw in Chrome 152.0.7977.82, affecting earlier Chrome versions, and urges prompt updates to Chrome stable desktop channels. Under BOD 26-04, Federal Civilian Executive Branch agencies must prioritize remediation on exposed assets and check for pre-patch compromise, with mitigation due 2026-09-18. CISA lists known ransomware campaign use as unknown.
- CVE: CVE-2026-85046.
- Vulnerability: Type confusion in Google Chromium's V8 JavaScript engine; it can allow arbitrary code execution inside the browser sandbox via a crafted HTML page.
- CWE: Cyber Security News identifies the issue as CWE-843.
- Exploitation: CISA lists the vulnerability as actively exploited; the Canadian Centre for Cyber Security says an exploit exists in the wild; Cyber Security News calls it a zero-day used in real attacks.
- Scope: CISA describes Chromium-based browsers including Google Chrome, Microsoft Edge, and Opera; Cyber Security News says Chrome is directly affected and Edge, Opera, and other Chromium-based browsers may be affected depending on their V8…
- Patch: Google fixed the issue in Chrome 152.0.7977.82; the Canadian Centre says it affects Chrome prior to that version and urges stable desktop Chrome updates.
- Advisory: The Canadian Centre for Cyber Security advisory is AV26-883, Update 1.
- KEV date: CISA added the vulnerability to the KEV catalog on 2026-09-04.
Coverage timelineoldest first · each row is one article
- · 12d agoCISA KEV: Google Chromium V8 Type Confusion Vulnerability — Google Chromium V8 (CVE-2026-85046)
CISA Known Exploited Vulnerabilities· 85
CISA added actively exploited Chromium V8 type confusion CVE-2026-85046 to the KEV catalog, requiring federal mitigation by September 18.
Vulnerabilities in this storyAll →
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2026-85046 | Actively Exploited V8 Type Confusion in Google Chrome (CVE-2026-85046) Google Chrome versions prior to 152.0.7977.82 contain a type confusion flaw (CWE-843) in the V8 JavaScript engine, which mishandles object types during engine operations (public proof-of-concept writeups indicate it is reachable through array sorting and WebAssembly-related code paths). A remote attacker triggers the flaw simply by getting a user to open a crafted HTML page, with no privileges or authentication required. Successful exploitation lets the attacker execute arbitrary code inside the browser's sandbox, and public reporting shows it being chained with Windows zero-days (the 'BlueMoon' exploit kit) by Chinese espionage groups for broader compromise. Any user of an unpatched Chrome or another build embedding the affected V8 engine is exposed. The vulnerability is a zero-day that was actively exploited in the wild before patching, was added to CISA's KEV on 2026-09-04, and has five public proof-of-concept references. Do: Update Google Chrome to 152.0.7977.82 or later immediately, and apply the corresponding V8 fix in any Chromium-based browser in use. Federal agencies must apply mitigations in line with CISA BOD 26-04 and its cloud-services requirements, evaluating each asset's internet exposure. Because public reporting shows this flaw chained with Windows zero-days in 'BlueMoon' attacks, patch the related Windows vulnerabilities as well and hunt for signs of exploit-chain activity on high-exposure endpoints. | 8.8 | 1% | KEV PoC ×5 |
| massmultiple billions of users/installs (Chrome is the dominant desktop browser at roughly 65% market share, with an estimated 3+ billion active users, plus… |