๐ฅ This vulnerability is being actively exploited in the wild (CISA Known Exploited Vulnerabilities catalog)
CVE-2026-85046: Google Chromium V8 Type Confusion Vulnerability
Summary
Google Chromium V8 has a type confusion vulnerability (a bug where the system treats data as the wrong type), allowing attackers to run malicious code through a crafted HTML page in web browsers like Chrome, Edge, and Opera. This flaw is currently being exploited by real attackers. Organizations must apply vendor patches by September 18, 2026, following CISA's BOD 26-04 guidance for prioritizing security updates, or stop using the product if no fix is available.
Solution / Mitigation
Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA's BOD 26-04 guidance. Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. See Google Chrome releases at https://chromereleases.googleblog.com/2026/09/stable-channel-update-for-desktop_01882797386.html for patch details.
Vulnerability Details
EPSS: 0.5%
Yes
๐ฅ Actively Exploited
September 3, 2026
Classification
Taxonomy References
Original source: https://nvd.nist.gov/vuln/detail/CVE-2026-85046
First tracked: September 4, 2026 at 02:01 PM
Classified by LLM (prompt v3) ยท confidence: 95%