CISA KEV Alert 9/4/2026, 9:01:06 PM

CISA Warns of Actively Exploited Chromium Flaw Allowing Code Execution

CyberSIXT Evidence Panel Source marked as original reporting
Primary Source cisa.gov
CISA KEV Listed in KEV
Patch Patch Available

CISA has added CVE-2026-85046 to its Known Exploited Vulnerabilities (KEV) catalogue. The vulnerability affects Google Chromium V8 and is a type confusion flaw that allows remote attackers to execute arbitrary code inside the browser sandbox through a crafted HTML page.

The flaw can be exploited remotely by serving a malicious HTML page to a vulnerable browser. Successful exploitation enables arbitrary code execution within the sandbox. Chromium-based browsers including Google Chrome, Microsoft Edge and Opera may be affected. The vulnerability carries a CVSS score of 8.8, rated High. A patch is available through Google’s stable channel update.

CISA has confirmed active exploitation, as indicated by the KEV listing. The available data does not confirm use in ransomware campaigns. Federal Civilian Executive Branch (FCEB) agencies must remediate the vulnerability by 18 September 2026.

CISA requires organisations to apply mitigations in accordance with vendor instructions, BOD 26-04 guidance on prioritising security updates based on risk, and its Forensics Triage Requirements. Agencies must evaluate each asset’s internet exposure, follow applicable patching guidance, and discontinue use if mitigations are unavailable. Although FCEB agencies are directly subject to this requirement, all organisations should review their exposure to Chromium-based browsers.

See the NVD entry and CISA KEV catalogue for full details.

View CISA KEV Entry

Article by CyberSIXT

Timeline Coverage

Swipe to explore timeline