← Blog · · df00tech

CISA Adds Chromium V8 Type Confusion Flaw (CVE-2026-85046) to KEV Catalog

breaking kev Google CVE-2026-85046

CISA has added CVE-2026-85046, a type confusion vulnerability in Google Chromium's V8 JavaScript engine, to its Known Exploited Vulnerabilities (KEV) catalog, indicating confirmed in-the-wild exploitation. According to Google's stable channel release notes, the flaw allows a remote attacker to execute arbitrary code inside the browser sandbox via a crafted HTML page. Because V8 underpins Chromium, the vulnerability is not limited to Google Chrome — it potentially affects any Chromium-based browser, including Microsoft Edge and Opera, though patch availability and timing may vary by vendor.

Why It Matters

Type confusion bugs in V8 are a recurring and historically reliable class of browser-exploitation primitive, frequently chained with a sandbox-escape bug for full system compromise. A crafted-webpage delivery vector means exploitation requires no more than getting a target to load a malicious or compromised page — a low-friction path for both opportunistic and targeted campaigns. Given the breadth of Chromium's install base across desktops, this represents a wide attack surface, and KEV inclusion signals defenders should treat patching as urgent rather than routine. CISA's KEV listing does not currently note known ransomware use, but that status can change as more is learned.

What Defenders Should Do

  • Confirm Chrome, Edge, Opera, and other Chromium-based browsers are updated to the patched stable channel release referenced in Google's advisory — verify via each browser's version/about page across managed fleets.
  • For CISA KEV-listed vulnerabilities affecting federal systems, remediation is mandated under BOD 22-01; private-sector defenders should treat the KEV listing as a strong prioritization signal regardless.
  • Where patching lags, consider interim mitigations such as site isolation enforcement, restricting execution of untrusted web content in higher-risk environments, and increased scrutiny of browser crash/renderer-process telemetry, which can surface exploitation attempts against V8 memory-corruption bugs.
  • Hunt for anomalous renderer sandbox escapes or unexpected child-process spawning from browser processes in EDR telemetry, a common downstream indicator of successful browser exploit chains.

This is a same-day, developing item based on a fresh CISA KEV addition; technical exploitation details, affected version ranges, and vendor-specific patch timelines are still emerging. For authoritative details, see Google's Chrome stable channel update announcement.

Get new detections in your inbox

New ATT&CK coverage plus CISA KEV / CVE detection rules, roughly weekly. No spam, unsubscribe anytime.