securityaffairs.com 9/4/2026, 11:57:17 PM · external

U.S. CISA adds Google Chromium V8 flaw to its Known Exploited Vulnerabilities catalog

U.S. CISA adds Google Chromium V8 flaw to its Known Exploited Vulnerabilities catalog
CyberSIXT Evidence Panel
Primary Source cisa.gov
CISA KEV Listed in KEV
Patch Patch Available

THE U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added a Google Chromium V8 flaw, tracked as CVE-2026-85046, to its Known Exploited Vulnerabilities catalog, with a CVSS score of 8.8. This vulnerability is a type confusion flaw in the Chrome browser's JavaScript and WebAssembly engine and allows remote attackers to execute arbitrary code via a specially crafted HTML page.

Google released a security update addressing this and 11 other vulnerabilities, marking CVE-2026-85046 as the sixth actively exploited Chrome zero-day of 2026. Security researcher Salvatore Gulizia reported the flaw and received a bug bounty. CISA requires federal agencies to remediate the issue by September 18, 2026.

View Primary Source Via securityaffairs.com

Article by CyberSIXT

Timeline Coverage

Swipe to explore timeline