DIRAS TAKE
Urgent: this defect is listed on CISA’s Known Exploited Vulnerabilities catalog with a federal remediation deadline, so prioritize updating or applying vendor mitigations immediately.
What is CVE-2026-85046?
Remote attackers can execute arbitrary code in Chromium V8 when a user opens a crafted HTML page. CVE-2026-85046 is a type confusion flaw that allows code execution inside the sandbox; it affects Chromium V8 branch 152.x before 152.0.7977.82 and was fixed in 152.0.7977.82. An attacker needs network access to deliver a malicious page and requires user interaction (the victim must load or interact with the crafted content).
Vector CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Which versions of Google Chromium V8 are affected?
| BRANCH | AFFECTED | FIXED |
|---|---|---|
| 152.x | 152.0.7977.82 – before 152.0.7977.82 | 152.0.7977.82 |
Is CVE-2026-85046 being exploited?
CISA added this vulnerability to the Known Exploited Vulnerabilities catalog on 2026-09-04, and U.S. federal agencies were required to remediate it by 2026-09-18.
How to fix CVE-2026-85046
- Upgrade Chromium-based products to 152.0.7977.82 or later.
- If you cannot update immediately, restrict exposure by blocking or isolating affected clients from untrusted web content.
- Follow vendor guidance and apply any recommended mitigations.
- Monitor endpoint telemetry for crashes or suspicious renderer activity and review web gateway logs for exploitation attempts.
Frequently asked questions
Is CVE-2026-85046 being actively exploited?
CISA added CVE-2026-85046 to the Known Exploited Vulnerabilities catalog on 2026-09-04, and federal agencies were required to remediate it by 2026-09-18.
Which Chromium V8 versions are affected by CVE-2026-85046?
Chromium V8 branch 152.x versions before 152.0.7977.82 are affected; the issue is fixed in 152.0.7977.82.
Is there a patch for CVE-2026-85046?
Yes. The vulnerability is fixed in Chromium V8 version 152.0.7977.82.
Does CVE-2026-85046 require authentication?
No authentication is required; an attacker can deliver a crafted HTML page over the network, but the exploit requires user interaction to load or engage with the malicious content.
References
- nvd.nist.gov/vuln/detail/CVE-2026-85046
- cve.org/CVERecord?id=CVE-2026-85046
- cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-85046
- chromereleases.googleblog.com/2026/09/stable-channel-update-for-desktop_01882797386.html
- issues.chromium.org/issues/542403045
- All Google CVEs on CVE Radar
- CVEs published in September 2026