THE U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added a Google Chromium V8 flaw, tracked as CVE-2026-85046, to its Known Exploited Vulnerabilities catalog, with a CVSS score of 8.8. This vulnerability is a type confusion flaw in the Chrome browser's JavaScript and WebAssembly engine and allows remote attackers to execute arbitrary code via a specially crafted HTML page.
Google released a security update addressing this and 11 other vulnerabilities, marking CVE-2026-85046 as the sixth actively exploited Chrome zero-day of 2026. Security researcher Salvatore Gulizia reported the flaw and received a bug bounty. CISA requires federal agencies to remediate the issue by September 18, 2026.