ZeroDayAlert

CVE-2026-85046: Google Chromium V8 Type Confusion Vulnerability

Google Chromium V8 contains a type confusion vulnerability that allows a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. This vulnerability could affect multiple web browsers that utilize Chromium, including, but not limited to, Google Chrome, Microsoft Edge, and Opera.

Google Chromium V8 Added to KEV 2026-09-04 Federal due 2026-09-18 Known ransomware use

Required action — quoted from CISA

Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.

Where this comes from. The identifier, product, dates and required action above are copied verbatim from the CISA Known Exploited Vulnerabilities catalog. The action plan below is written by an AI agent from that record and published automatically. AssurePort has not independently tested this vulnerability and makes no claim about whether any specific system is affected.

Who is affected

This affects the V8 JavaScript engine within Chromium and any browser built on Chromium. This includes Google Chrome, Microsoft Edge, Opera, and other Chromium derivatives across Windows, macOS, Linux, Android, and iOS. The vulnerability allows remote code execution within the browser sandbox via a crafted HTML page delivered to a user. Any organisation or individual relying on these browsers is potentially in scope.

How to check whether this touches you

  • Inventory all devices and users running Chrome, Edge, Opera, or other Chromium-based browsers, paying attention to managed deployments and developer machines.
  • Establish whether these browsers are exposed to untrusted web content from the internet or via email links; intranet-only browsers face lower attack surface.
  • Confirm the running browser version by opening the browser's "About" or settings menu, which will show the current version number and whether updates are pending. A version number alone does not prove the presence or absence of a backported fix; cross-reference with your vendor's security advisory for your specific release train.
  • For enterprise deployments, check whether auto-update is enabled or whether updates are gated by policy; the latter may delay patch availability.

What to do

  1. Obtain the vendor patch from Google (Chrome), Microsoft (Edge), or Opera as applicable, and review any associated security advisory to confirm the fix applies to your version.
  2. If you cannot patch immediately, restrict user access to untrusted websites and disable JavaScript execution for content from low-trust sources where operationally feasible.
  3. Reduce external reachability by blocking or filtering suspicious HTML attachments and links in email at the gateway if your environment does not require them.
  4. Enable and review browser security logs, crash reports, and sandbox escape attempts; configure logging retention to at least 90 days to support retrospective investigation.
  5. Prioritise patching according to CISA BOD 26-04 timelines, treating internet-facing and high-value user devices first.
  6. Escalate to security operations if you observe unusual browser crashes, unexpected script execution, or signs of sandboxed code breaking out into the host system.

If you find you were exposed

Exploitation of type confusion flaws often predates public disclosure, so you should hunt backwards through logs from at least 60 to 90 days before the patch release date. Focus on browser crash dumps, sandbox violations, and any evidence of suspicious processes spawned from the browser process. Check endpoint detection and response (EDR) or security information and event management (SIEM) systems for indicators of abnormal browser behaviour. If your log retention does not cover this window, document the gap and prioritise extending retention for future incidents.

Get these the morning they land.

One email, only when a vulnerability is newly confirmed as exploited — the CISA record plus our action plan. No more than one a day, and nothing on quiet days.

Knowing it exists is not the same as knowing you are exposed.

This page can tell you that CVE-2026-85046 is being exploited. It cannot tell you whether Chromium V8 is running somewhere of yours that is reachable. That question is what a scan answers.

Check your own surface →