Skip to content
See the World Through ScienceA project of ALLATRA

CISA Flags Actively Exploited Chrome Flaw: Patch Already Shipped

AI & Technology

Republish this story

Our work is licensed under Creative Commons BY-NC 4.0. You may republish this piece for free — with credit to ALLATRA Media and a link to the original, unedited beyond length trims, and not for commercial use.

Read the full license

A silver Samsung Chromebook laptop, open and switched on, resting on its box, which carries the Google Chrome logo.
Google's Chrome software, whose V8 JavaScript engine carries the flaw CISA listed as actively exploited; every Chromium-based browser shares that engine. Illustrative device photograph."The Google Chromebook Laptop by Samsung" by Mom and Son Media and Content (Carol Rucker & Greg, via flickr, CC-BY-SA-2.0 · CC-BY-SA-2.0

The US Cybersecurity and Infrastructure Security Agency added CVE-2026-85046, a type-confusion flaw in Google Chrome's V8 JavaScript engine, to its Known Exploited Vulnerabilities catalog on Sept. 4, 2026, citing evidence of active exploitation. Google had shipped the fix to Chrome's Stable channel the day before, on Sept. 3.

The KEV listing is CISA's formal signal that the flaw was being used in real attacks before the patch arrived. V8 is the JavaScript engine shared by Chrome and every Chromium-based browser, including Edge, Brave and Opera.

CISA describes type-confusion vulnerabilities as "a frequent attack vector for malicious cyber actors" that "pose significant risks to the federal enterprise." Under Binding Operational Directive 26-04, federal civilian agencies must prioritize remediation of KEV-listed flaws. The agency added that it "encourages all organizations to adopt risk-based vulnerability management and prioritize remediation of KEV Catalog vulnerabilities."

No specific actor or campaign behind the exploitation was named, and no scale or victim count was stated.

Chrome updates automatically for most users; anyone who has deferred updates should open Chrome's settings and check for the current version. Chromium-based browsers that package their own V8 builds will carry the fix in their own update cycles.

Sources

Spot an error?

Spot an error?

Report an error

Spotted a mistake on this page? Tell us what's wrong and our editors will take a look.

What kind of problem?

Only if you'd like us to be able to follow up. We won't use it for anything else.

We correct mistakes openly. Select any text to flag it. Fixes are logged under our Corrections Policy.

Report an error

Reporting on

CISA Flags Actively Exploited Chrome Flaw: Patch Already Shipped

What kind of problem?

Only if you'd like us to be able to follow up. We won't use it for anything else.

We read every report. Corrections are logged publicly.