Chromium Zero-Day CVE-2026-85046 Exploited

Actively exploited Chromium V8 zero-day requires urgent Chrome and Edge updates

A Chromium zero-day tracked as CVE-2026-85046 is being actively exploited, according to a CISA warning reported on 8 September 2026. The vulnerability affects the V8 engine at the heart of Google Chrome and potentially other Chromium-based browsers.

CISA has added the flaw to its Known Exploited Vulnerabilities (KEV) Catalog, indicating that exploitation has moved beyond a theoretical risk. Google has also released a Stable Channel update for Chrome desktop users, making browser updates an immediate priority for organisations.

Chromium zero-day added to CISA’s KEV catalogue

CVE-2026-85046 is a type confusion vulnerability in Chromium’s V8 JavaScript and WebAssembly engine. V8 processes JavaScript and WebAssembly content delivered by websites, placing the affected component directly in the path of content encountered during routine browsing.

The issue is classified as CWE-843, or access of a resource using an incompatible type. Type confusion happens when software mistakenly treats an object as a different type from the one it was designed to handle. In a browser engine, that mistake can result in unsafe memory operations and create an opportunity for an attacker to execute code.

The Chromium zero-day can reportedly be triggered remotely. An attacker would need to persuade a user to load a specially crafted HTML page, which could be hosted on a malicious website or delivered through a link directing the victim to attacker-controlled content.

If exploitation succeeds, the attacker may gain arbitrary code execution inside the browser sandbox. This sandbox is intended to isolate web content from the wider operating system, so execution inside it does not automatically mean that the attacker has taken full control of the device.

However, code execution within the browser remains serious. It could expose information available to the browser, support credential theft, initiate malicious downloads, enable surveillance or provide a starting point for a second vulnerability designed to escape the sandbox. The available report does not confirm that CVE-2026-85046 has been combined with a separate sandbox escape.

Products potentially affected by CVE-2026-85046

Google Chrome is directly affected because it uses the vulnerable Chromium V8 engine. The broader concern is that Chromium also provides the technical foundation for several other widely deployed browsers.

Microsoft Edge and Opera could be affected depending on the Chromium and V8 versions incorporated into each release. Other products that embed Chromium may also require review, although the report does not identify additional applications or confirm their exposure.

The source report does not provide exact affected or fixed browser version numbers. It only states that Google has published a Stable Channel update for Chrome desktop. Administrators should therefore obtain the applicable build information from each browser vendor rather than assume that one Chrome update resolves every Chromium-based product.

Relevant products to review include:

  • Google Chrome desktop installations using a vulnerable V8 build.
  • Microsoft Edge releases based on an affected Chromium version.
  • Opera releases incorporating the vulnerable V8 engine.
  • Other managed applications or browsers that embed Chromium components.

This distinction matters in environments where employees can install or use multiple browsers. Updating Chrome will not update Edge, Opera or a separate application with its own embedded Chromium runtime.

Chromium zero-day exploitation status and timeline

The report was published on 8 September 2026 and stated that CISA had added CVE-2026-85046 to the KEV catalogue. Inclusion in the catalogue means CISA has evidence of active exploitation, rather than simply considering exploitation technically possible.

No information has been provided about the threat actor or actors using the Chromium zero-day. The report also does not identify targeted countries, industries, organisations or individual victims. It does not describe the number of attacks or indicate whether exploitation is widespread or limited to a smaller campaign.

CISA’s ransomware campaign field is listed as unknown. This means there is no confirmed information in the report linking CVE-2026-85046 to ransomware activity, but it should not be interpreted as evidence that such use is impossible.

The precise date on which exploitation began is also not stated. There is no disclosed timeline covering initial discovery, reporting to Google, development of the patch or the first observed attack. What is established is that active exploitation had been recognised and a Chrome Stable Channel update was available by the time of the 8 September 2026 report.

CISA has instructed stakeholders to apply vendor-recommended mitigations in line with its BOD 26-04 risk-based patching guidance. Where mitigations are not available, its guidance is to discontinue use of affected products. The report does not provide a specific remediation deadline or require a particular forensic triage process.

Why this Chromium zero-day matters

Browsers occupy a sensitive position in modern working environments. They are routinely used to open corporate email, administer cloud services, access source code, manage financial platforms and authenticate to software as a service applications.

A Chromium zero-day that can be reached through a crafted web page gives attackers a potential route into these sessions. The need for user interaction may be limited to opening a link or visiting a compromised page, although the report does not detail the delivery methods seen in current attacks.

The confirmed exploitation status also changes the risk calculation. Organisations should treat CVE-2026-85046 as an observed threat and not wait for public details about the attacker, exploit code or victim profile before deploying available updates.

Actions for organisations using Chromium browsers

Organisations should first use their browser management or endpoint management platforms to identify installed Chrome, Edge, Opera and other Chromium-based products. They should then compare deployed builds with the latest security releases published by the relevant vendor.

Priority actions directly related to this incident are:

  • Deploy Google’s Chrome Stable Channel update through enterprise management tools.
  • Check Microsoft Edge, Opera and embedded Chromium products for separate vendor updates.
  • Verify the installed version after deployment, rather than relying only on an update job’s completion status.
  • Confirm that automatic browser updates are enabled and functioning on managed endpoints.
  • Identify devices running unsupported operating systems or browser versions that cannot receive the fix.
  • Review web proxy, browser and endpoint telemetry for unusual activity associated with newly visited or untrusted domains.

Security teams investigating possible exposure should remember that exploitation may occur within the browser sandbox. Alerts involving unexpected browser child processes, suspicious downloads or unusual activity following a website visit may justify closer examination, but none of these behaviours alone proves exploitation of CVE-2026-85046.

Until each vendor confirms a patched version, organisations should avoid assuming that all Chromium products are protected. The immediate objective is to remove vulnerable browser builds and confirm that updates have reached the endpoints employees actually use.

Originally reported by cybersecuritynews.com.

Share this bulletin

About the Author

Headshot of Jonny Pelter, leading cyber security expert in the UK and CISO

Jonny Pelter

Partner

  • CIPM
  • CIPP/E
  • CISSP
  • CISM
  • CRISC
  • ISO27001
  • Prince2
  • MSc
  • BSc

Jonny Pelter

Jonny is a Founding Partner at CyPro and executive group level CISO who has worked closely with the British intelligence agencies NCSC and GCHQ.

An ex-professional rugby player and originating from KPMG and Deloitte, Jonny has a wealth of experience across numerous sectors including technology, critical national infrastructure, financial services, oil & gas, insurance, betting, pharmaceuticals and utilities.

Jonny is a leading cyber security expert in the UK, having featured on national media for his professional commentary such as BBC News, iPlayer, Telegraph and Times Radio.

View Profile
Back to Bulletins

Related CyPro Services

  • Managed Detection and Response (MDR)

    Managed Detection and Response (MDR) is an end-to-end managed service designed to help organisations detect, analyse and respond to cyber threats quickly and effectively. It...
    View Service
CyPro Cookie Consent

Hmmm cookies...

Our delicious cookies make your experience smooth and secure.

Privacy PolicyOkay, got it!

We use cookies to enhance your experience, analyse site traffic, and for marketing purposes. For more information on how we handle your personal data, please see our Privacy Policy.

Schedule a Call