Search
Find merged stories by title or summary.
CISA Warns of Chromium Type Confusion 0-Day Vulnerability Actively Exploited in Attacks
CISA has added a critical Google Chromium V8 type confusion vulnerability, tracked as CVE-2026-85046 , to its Known Exploited Vulnerabilities (KEV) Catalog, warning that the flaw is being actively exploited in attacks. CVE-2026-85046 affects the V8 JavaScript and WebAssembly engine used by Chromium-based browsers. The vulnerability stems from type confusion, classified under CWE-843, a weakness that occurs when software incorrectly handles an object as though it were a different data type. In a browser engine, this can lead to unexpected memory behavior and potentially provide attackers with a path to execute arbitrary code. According to the vulnerability description, a remote attacker could exploit CVE-2026-85046 by persuading a target to load a specially crafted HTML page. Successful exploitation may enable arbitrary code execution inside the browser sandbox.
U.S. CISA adds Google Chromium V8 flaw to its Known Exploited Vulnerabilities catalog
U. S. Cybersecurity and Infrastructure Security Agency (CISA) adds Google Chromium V8 flaw to its Known Exploited Vulnerabilities catalog. The U. S. Cybersecurity and Infrastructure Security Agency (CISA) added a Google Chromium V8 flaw, tracked as CVE-2026-85046 (CVSS score of 8,8), to its Known Exploited Vulnerabilities (KEV) catalog . This week, Google released a Chrome security update fixing 12 vulnerabilities, including CVE-2026-85046, an actively exploited V8 type confusion flaw. The bug affects Chrome’s JavaScript and WebAssembly engine and could let a remote attacker execute arbitrary code inside the browser sandbox by using a specially crafted HTML page. “CVE-2026-85046: Type confusion in V8.” reads the advisory . “Google is aware that an exploit for CVE-2026-85046 exists in the wild.”
Google security advisory (AV26-883)
Serial Number: AV26-883 Date: September 4, 2026 As of September 3, 2026, Google is affected by vulnerabilities in the following product: • Chrome • Prior to 152.0.7977.82 Google is aware that an exploit for CVE-2026-85046 exists in the wild. The Cyber Centre encourages users and administrators to review the provided web link and apply any necessary updates as they become available. • Stable Channel Update for Desktop Google security advisory (AV26-883) - Canadian Centre for Cyber Security
Google patches actively exploited Chrome zero-day (CVE-2026-85046)
Google has patched 12 vulnerabilities affecting its popular Chrome browser, among them CVE-2026-85046, which has been exploited in the wild. “Google is aware that an exploit for CVE-2026-85046 exists in the wild,” the company said in a Thursday security advisory. The fix has been shipped in Chrome 152. 0. 7977. 82/. 83 for Windows and macOS and Chrome 152. 0. 7977. 82 for Linux, with the update rolling out to users over the coming days and weeks. About CVE-2026-85046 CVE-2026-85046 (CVSS score: … More → The post Google patches actively exploited Chrome zero-day (CVE-2026-85046) appeared first on Help Net Security .
CISA Adds One Known Exploited Vulnerability to Catalog
CISA has added one new vulnerability to its Known Exploited Vulnerabilities (KEV) Catalog , based on evidence of active exploitation. • CVE-2026-85046 Google Chromium V8 Type Confusion Vulnerability This type of vulnerability is a frequent attack vector for malicious cyber actors and poses significant risks to the federal enterprise. Binding Operational Directive (BOD) 26-04: Prioritizing Security Updates Based on Risk establishes vulnerability management requirements for Federal Civilian Executive Branch (FCEB) agencies.
Google fixes actively exploited Chrome V8 zero-day vulnerability
Google has released a Chrome security update addressing 12 vulnerabilities, including a high-severity V8 flaw that is being actively exploited in attacks. The fixes are included in Chrome 152. 0. 7977. 82/. 83 for Windows and macOS and version 152. 0. 7977. 82 for Linux, with deployment taking place gradually. The actively exploited vulnerability is tracked as CVE-2026-85046 and is described as … The post Google fixes actively exploited Chrome V8 zero-day vulnerability appeared first on CyberInsider .
Google fixes the sixth actively exploited Chrome zero-day of 2026
Google patched 12 Chrome flaws, including an actively exploited V8 zero-day that could enable remote code execution through a crafted webpage. Google released a Chrome security update fixing 12 vulnerabilities, including CVE-2026-85046 (CVSS score of 8.8), an actively exploited V8 type confusion flaw. The bug affects Chrome’s JavaScript and WebAssembly engine and could let a remote attacker execute arbitrary code inside the browser sandbox by using a specially crafted HTML page. “CVE-2026-85046: Type confusion in V8.” reads the advisory . “Google is aware that an exploit for CVE-2026-85046 exists in the wild.” As usual, Google did not disclose technical details about the attacks exploiting this vulnerability or attribute them to any specific threat actor. Security researcher Salvatore Gulizia, known as Serotav, reported the flaw on August 4, 2026, and received a $1,000 bug bounty.
Google Releases Chrome Update to Patch Actively Exploited V8 Zero-Day
Google on Thursday released security updates to patch 12 vulnerabilities, including one that has come under active exploitation in the wild. The high-severity vulnerability, tracked as CVE-2026-85046 (CVSS score: 8.8), has been described as a type confusion bug in V8, Chrome's JavaScript and WebAssembly engine. "Type confusion in V8 in Google Chrome prior to 152. 0. 7977. 82 allowed a remote
CVE-2026-85046 - Google Chrome V8 Type Confusion Vulnerability
Google Chromium V8 contains a type confusion vulnerability that allows a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. This vulnerability could affect multiple web browsers that utilize Chromium, including, but not limited to, Google Chrome, Microsoft Edge, and Opera.
NVD-CVE-2026-85046 - National Institute of Standards and Technology (.gov)
NVD-CVE-2026-85046 National Institute of Standards and Technology (.gov)
You've reached the end of current stories for this search.
