Cyber Security News

CISA Warns of Chromium Type Confusion 0-Day Vulnerability Actively Exploited in Attacks

CISA has added a critical Google Chromium V8 type confusion vulnerability, tracked as CVE-2026-85046, to its Known Exploited Vulnerabilities (KEV) Catalog, warning that the flaw is being actively exploited in attacks.

CVE-2026-85046 affects the V8 JavaScript and WebAssembly engine used by Chromium-based browsers. The vulnerability stems from type confusion, classified under CWE-843, a weakness that occurs when software incorrectly handles an object as though it were a different data type. In a browser engine, this can lead to unexpected memory behavior and potentially provide attackers with a path to execute arbitrary code.

According to the vulnerability description, a remote attacker could exploit CVE-2026-85046 by persuading a target to load a specially crafted HTML page. Successful exploitation may enable arbitrary code execution inside the browser sandbox.

Although browser sandboxing is an important security boundary designed to limit the impact of malicious web content, code execution within that environment can still expose users to credential theft, malicious downloads, surveillance, or follow-on exploitation attempts.

Chromium Type Confusion 0-Day

The issue is particularly significant because Chromium serves as the foundation for several widely deployed browsers. Google Chrome is directly affected, while other Chromium-based products, including Microsoft Edge and Opera, could also be impacted depending on their V8 and Chromium version.

Organizations should not assume that patching Chrome alone addresses their exposure; security teams should inventory all managed browsers and verify available vendor updates for each platform.

CISA’s KEV designation indicates that exploitation is not merely theoretical. The agency did not state whether CVE-2026-85046 has been used in ransomware operations, and the ransomware-campaign field is currently listed as unknown.

Binding Operational Directive 26-04 does not specify a forensic triage requirement, but CISA recommends that organizations apply vendor-recommended mitigations and evaluate the internet exposure of affected assets.

Google has published a Stable Channel update for Chrome desktop users, and administrators should prioritize deployment through enterprise update-management tools.

Security teams should also confirm that automatic browser updates are enabled, identify endpoints running unsupported operating systems or outdated browser builds, and monitor web proxy, endpoint, and browser telemetry for suspicious activity involving newly visited or untrusted domains.

For enterprises, the urgency extends beyond standard patching. Browsers are routinely used to access cloud administration portals, corporate email, source-code repositories, and SaaS platforms, making an actively exploited browser flaw a valuable initial-access opportunity.

Restricting unnecessary browser extensions, enforcing phishing-resistant MFA, and maintaining endpoint detection coverage can reduce the damage if browser-based exploitation occurs.

CISA has instructed stakeholders to apply mitigations consistent with BOD 26-04 risk-based patching guidance or discontinue use of affected products when mitigations are unavailable.

Learn 7 Metric-Gated AI SOC Deployment Phases – Download Free AI SOC Deployment Playbook 2026.

Guru Baran

Gurubaran KS is a cybersecurity analyst, and Journalist with a strong focus on emerging threats and digital defense strategies. He is the Co-Founder and Editor-in-Chief of Cyber Security News, where he leads editorial coverage on global cybersecurity developments.

Recent Posts

Google Chrome 153 Update Fixes 42 Security Flaws, Including 3 Critical Ones

Google has released an important Chrome 153 security update that fixes 42 vulnerabilities across the…

4 hours ago

CISA and NIST Release Technical Checklist for Safeguarding Identity Tokens From Theft and Misuse

The Cybersecurity and Infrastructure Security Agency (CISA) and the National Institute of Standards and Technology…

14 hours ago

CISA Shares 17 Techniques Used by Hackers to Compromise Active Directory Environments

CISA and five international cybersecurity agencies have released detailed guidance describing 17 common techniques hackers…

15 hours ago

Apple Rolls Out Massive Security Update Fixing 273 Vulnerabilities Across Its Devices

Apple has released one of its largest coordinated security rollouts, addressing 273 distinct critical vulnerabilities…

15 hours ago

How to Keep Malware’s Rotating Infrastructure From Becoming a Detection Gap

You can’t detect today's attacks with yesterday’s threat intelligence; that’s how you could briefly formulate…

15 hours ago

Microsoft Bans Its AI Models From Launching Cyberattacks or Escalating Their Own Access

Microsoft has published a draft Humanist AI Code of Conduct that would prohibit its in-house…

16 hours ago