Users and administrators should update Google Chrome and Chromium-based browsers to the latest available version. CISA encourages organizations to apply security updates promptly and adopt risk-based vulnerability management practices. Federal agencies must follow BOD 26-04 requirements for prioritizing KEV Catalog remediation on publicly exposed assets.
Quick answers
What is CVE-2026-85046?
Users and administrators should update Google Chrome and Chromium-based browsers to the latest available version. CISA encourages organizations to apply security updates promptly and adopt risk-based vulnerability management practices. Federal agencies must follow BOD 26-04 requirements for prioritizing KEV Catalog remediation on publicly exposed assets.
How severe is CVE-2026-85046?
high
Is CVE-2026-85046 known to be exploited?
It is not marked known-exploited in this record.
How should CVE-2026-85046 be mitigated?
Users and administrators should update Google Chrome and Chromium-based browsers to the latest available version. CISA encourages organizations to apply security updates promptly and adopt risk-based vulnerability management practices. Federal agencies must follow BOD 26-04 requirements for prioritizing KEV Catalog remediation on publicly exposed assets.
CVSS
—
Vendor
Google
Published
Sep 30, 2026 · 08:42
Patch
Unknown / not confirmed
Affected products
Google Chromium, Google Chrome
Mitigation
Users and administrators should update Google Chrome and Chromium-based browsers to the latest available version. CISA encourages organizations to apply security updates promptly and adopt risk-based vulnerability management practices. Federal agencies must follow BOD 26-04 requirements for prioritizing KEV Catalog remediation on publicly exposed assets.
A Chinese threat actor tracked as UTA0565 has been observed exploiting a chain of three zero-day vulnerabilities - two in Google Chrome and one in Microsoft Windows - to deploy CLEANGULP malware. The attacks, detected in early September 2026, targeted users visiting fake websites and leveraged the exploit chain to achieve remote code execution and malware deployment. Google and Microsoft are expected to release security updates to address the vulnerabilities CVE-2026-85046, CVE-2026-87491, and CVE-2026-85880.
Google has released security updates for Chrome, patching 12 vulnerabilities including CVE-2026-85046, a high-severity type confusion bug in the V8 JavaScript and WebAssembly engine that is being actively exploited in the wild. The flaw affects Chrome versions prior to 152.0.7977.82 and could allow remote attackers to execute arbitrary code. Users are urged to update immediately.
The Cybersecurity and Infrastructure Security Agency (CISA) has added CVE-2026-85046, a Google Chromium V8 type confusion vulnerability, to its Known Exploited Vulnerabilities (KEV) Catalog. The addition is based on evidence of active exploitation in the wild. CISA's Binding Operational Directive 26-04 requires Federal Civilian Executive Branch agencies to prioritize rapid remediation of KEV Catalog vulnerabilities on publicly exposed assets and verify whether compromise occurred before patching. All organizations are encouraged to update affected browsers promptly.