Skip to main content

Google Chrome V8 Type Confusion Zero-Day Under Active Exploitation Added to CISA KEV (CVE-2026-85046)

Scope: Google Chrome Prior to Version 152.0.7977.82 and All Chromium-Based Browsers Including Microsoft Edge, Brave, and Opera

Severity: High

CVE-2026-85046 (CVSS 8.8) is the seventh actively exploited Chrome zero-day in 2026, a type confusion vulnerability in Chrome's V8 JavaScript and WebAssembly engine discovered by researcher Salvatore Gulizia and patched on September 9, 2026. A remote attacker can execute arbitrary code inside the Chrome sandbox by directing a victim to a specially crafted web page, with no additional user interaction required beyond visiting the malicious page. CISA added this to its KEV catalog on September 4 with a federal deadline of September 18, 2026. All users must update Chrome to version 152.0.7977.82 or later immediately via the Chrome menu, Help, About Google Chrome, and users of Edge, Brave, Opera, and other Chromium-based browsers must apply their respective updates as they become available.

The Uganda National CERT and Coordination Center (CERT.UG/CC) encourages users and administrators to review the recommendations and apply the necessary updates.