CISA Flags Actively Exploited Chrome Flaw: Patch Already Shipped

The US Cybersecurity and Infrastructure Security Agency added CVE-2026-85046, a type-confusion flaw in Google Chrome's V8 JavaScript engine, to its Known Exploited Vulnerabilities catalog on Sept. 4, 2026, citing evidence of active exploitation. Google had shipped the fix to Chrome's Stable channel the day before, on Sept. 3.
The KEV listing is CISA's formal signal that the flaw was being used in real attacks before the patch arrived. V8 is the JavaScript engine shared by Chrome and every Chromium-based browser, including Edge, Brave and Opera.
CISA describes type-confusion vulnerabilities as "a frequent attack vector for malicious cyber actors" that "pose significant risks to the federal enterprise." Under Binding Operational Directive 26-04, federal civilian agencies must prioritize remediation of KEV-listed flaws. The agency added that it "encourages all organizations to adopt risk-based vulnerability management and prioritize remediation of KEV Catalog vulnerabilities."
No specific actor or campaign behind the exploitation was named, and no scale or victim count was stated.
Chrome updates automatically for most users; anyone who has deferred updates should open Chrome's settings and check for the current version. Chromium-based browsers that package their own V8 builds will carry the fix in their own update cycles.
