Cyber & AI intelligence
Wasteland.
Briefs indexed2425
Issues26
Published Mondays07:30 CT
⚡ Active KEV CVE-2026-85046 2026-09-04

CVE-2026-85046: Actively Exploited Chromium V8 Type Confusion Lands on CISA KEV

"CISA added CVE-2026-85046 to the Known Exploited Vulnerabilities catalog on September 4, 2026, confirming active exploitation of a high-severity type confusion flaw in Chromium's V8 JavaScript engine."

CISA added CVE-2026-85046 to the Known Exploited Vulnerabilities catalog on September 4, 2026, confirming active exploitation of a high-severity type confusion flaw in Chromium's V8 JavaScript engine.

What Is It

CVE-2026-85046 is a type confusion vulnerability (CWE-843) in V8, the JavaScript engine used by Google Chrome and other Chromium-based browsers. Per NVD, the flaw exists in Google Chrome prior to version 152.0.7977.82 and allows a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. Google rates the Chromium security severity as High.

The CVSS 3.1 base score is 8.8 (HIGH), vector AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H, network-reachable, low complexity, no privileges required, but requiring user interaction, with high impact to confidentiality, integrity, and availability.

Why It Matters

CISA's KEV listing confirms this vulnerability is under active exploitation in the wild. CISA's SSVC decision points record exploitation as "active" with a technical impact of "total," though the vulnerability is assessed as not automatable. Known ransomware campaign use is listed as Unknown.

The attack path is a crafted HTML page, meaning a single visit to attacker-controlled or attacker-influenced content may be sufficient to trigger code execution inside the renderer sandbox. Chromium's ubiquity suggests the blast radius likely extends beyond Chrome itself.

What's Vulnerable

Patch Status

Google addressed the issue in the Chrome stable channel update for desktop published September 2026. Update to 152.0.7977.82 or later; Chromium-derived browsers should be updated to the vendor build incorporating the fix.

CISA's required action is to apply mitigations in accordance with vendor instructions, ensuring compliance with BOD 26-04 "Prioritizing Security Updates Based on Risk" and CISA's Forensics Triage Requirements. Follow applicable BOD 26-04 guidance for cloud services, or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure. The KEV remediation due date is September 18, 2026. Forensic triage is flagged "No" for this entry.

Sources