CISA has added CVE-2026-85046 to its Known Exploited Vulnerabilities (KEV) catalogue. The vulnerability affects Google Chromium V8 and is a type confusion flaw that allows remote attackers to execute arbitrary code inside the browser sandbox through a crafted HTML page.
The flaw can be exploited remotely by serving a malicious HTML page to a vulnerable browser. Successful exploitation enables arbitrary code execution within the sandbox. Chromium-based browsers including Google Chrome, Microsoft Edge and Opera may be affected. The vulnerability carries a CVSS score of 8.8, rated High. A patch is available through Google’s stable channel update.
CISA has confirmed active exploitation, as indicated by the KEV listing. The available data does not confirm use in ransomware campaigns. Federal Civilian Executive Branch (FCEB) agencies must remediate the vulnerability by 18 September 2026.
CISA requires organisations to apply mitigations in accordance with vendor instructions, BOD 26-04 guidance on prioritising security updates based on risk, and its Forensics Triage Requirements. Agencies must evaluate each asset’s internet exposure, follow applicable patching guidance, and discontinue use if mitigations are unavailable. Although FCEB agencies are directly subject to this requirement, all organisations should review their exposure to Chromium-based browsers.
See the NVD entry and CISA KEV catalogue for full details.