Actively exploited
Listed in CISA’s Known Exploited Vulnerabilities catalog since September 4, 2026.
CVE-2026-85046
Google Chromium V8 Type Confusion Vulnerability
Added to KEV September 4, 2026
Alert details
- Source feed
- CISA KEV
- CVE ID
- CVE-2026-85046
- CWE
- CWE-843
- Affected products
- Chromium V8 · Google Chromium V8 · Google
What happened
Google Chromium V8 contains a type confusion vulnerability that allows a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. This vulnerability could affect multiple web browsers that utilize Chromium, including, but not limited to, Google Chrome, Microsoft Edge, and Opera.
What it means for your business
Google Chromium V8 is listed in CISA's Known Exploited Vulnerabilities catalog (CVE-2026-85046). Google Chromium V8 contains a type confusion vulnerability that allows a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. This vulnerability could affect multiple web browsers that utilize Chromium, including, but not limited to, Google Chrome, Microsoft Edge, and Opera. CISA remediation due date: 2026-09-18. If you need help checking exposure, call (864) 335-9223.
Required action
Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
CISA due date: September 18, 2026
Sources
Related briefs
Google Chromium V8 Out of Bounds Write Vulnerability
Google Chromium V8 is listed in CISA's Known Exploited Vulnerabilities catalog (CVE-2026-87491). Google Chromium V8 contains an out of bounds write vulnerability that allows a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. This vulnerability could affect multiple web browsers that utilize Chromium, including, but not limited to, Google Chrome, Microsoft Edge, and Opera. CISA remediation due date: 2026-09-23. If you need help checking exposure, call (864) 335-9223.
Google Pixel Improper Authorization Vulnerability
Google Pixel is listed in CISA's Known Exploited Vulnerabilities catalog (CVE-2026-58704). Google Pixel devices contain an improper authorization vulnerability in the cellular modem. A logic error may allow an attacker to bypass permission checks and escalate privileges. CISA remediation due date: 2026-09-19. If you need help checking exposure, call (864) 335-9223.
Microsoft Edge (Chromium-based) Elevation of Privilege vulnerability
Microsoft Edge (Chromium-based) Elevation of Privilege vulnerability (CVE-2026-88097) was added to Microsoft’s security update guidance. <p>Use after free in Microsoft Edge (Chromium-based) allows an unauthorized attacker to elevate privileges locally.</p> If you need help checking exposure, call (864) 335-9223.
Linux Kernel Out-of-Bounds Write Vulnerability
Linux Kernel is listed in CISA's Known Exploited Vulnerabilities catalog (CVE-2026-53266). Linux Kernel contains an out-of-bounds write vulnerability in the ebtables SNAT target which allows an ARP sender hardware address rewrite to write directly into a nonlinear socket-buffer fragment backed by a splice-imported file page. The impacted product(s) could be end-of-life (EoL) and/or end-of-service (EoS). Users are advised to discontinue use and/or transition to a supported version. CISA remediation due date: 2026-09-21. If you need help checking exposure, call (864) 335-9223.
Need help patching?
PremierePC monitors KEV alerts for managed clients and helps teams prioritize remediation before attackers do.