CISA Warns of Chromium Type Confusion 0-Day Vulnerability Actively Exploited in Attacks

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Spread the love

CISA has added a critical Google Chromium V8 type confusion vulnerability, tracked as CVE-2026-85046, to its Known Exploited Vulnerabilities (KEV) Catalog, warning that the flaw is being actively exploited in attacks.

CVE-2026-85046 affects the V8 JavaScript and WebAssembly engine used by Chromium-based browsers. The vulnerability stems from type confusion, classified under CWE-843, a weakness that occurs when software incorrectly handles an object as though it were a different data type. In a browser engine, this can lead to unexpected memory behavior and potentially provide attackers with a path to execute arbitrary code.

According to the vulnerability description, a remote attacker could exploit CVE-2026-85046 by persuading a target to load a specially crafted HTML page. Successful exploitation may enable arbitrary code execution inside the browser sandbox.

Although browser sandboxing is an important security boundary designed to limit the impact of malicious web content, code execution within that environment can still expose users to credential theft, malicious downloads, surveillance, or follow-on exploitation attempts.

Chromium Type Confusion 0-Day

The issue is particularly significant because Chromium serves as the foundation for several widely deployed browsers. Google Chrome is directly affected, while other Chromium-based products, including Microsoft Edge and Opera, could also be impacted depending on their V8 and Chromium version.

Organizations should not assume that patching Chrome alone addresses their exposure; security teams should inventory all managed browsers and verify available vendor updates for each platform.

CISA’s KEV designation indicates that exploitation is not merely theoretical. The agency did not state whether CVE-2026-85046 has been used in ransomware operations, and the ransomware-campaign field is currently listed as unknown.

Binding Operational Directive 26-04 does not specify a forensic triage requirement, but CISA recommends that organizations apply vendor-recommended mitigations and evaluate the internet exposure of affected assets.

Google has published a Stable Channel update for Chrome desktop users, and administrators should prioritize deployment through enterprise update-management tools.

Security teams should also confirm that automatic browser updates are enabled, identify endpoints running unsupported operating systems or outdated browser builds, and monitor web proxy, endpoint, and browser telemetry for suspicious activity involving newly visited or untrusted domains.

For enterprises, the urgency extends beyond standard patching. Browsers are routinely used to access cloud administration portals, corporate email, source-code repositories, and SaaS platforms, making an actively exploited browser flaw a valuable initial-access opportunity.

Restricting unnecessary browser extensions, enforcing phishing-resistant MFA, and maintaining endpoint detection coverage can reduce the damage if browser-based exploitation occurs.

CISA has instructed stakeholders to apply mitigations consistent with BOD 26-04 risk-based patching guidance or discontinue use of affected products when mitigations are unavailable.

Learn 7 Metric-Gated AI SOC Deployment Phases – Download Free AI SOC Deployment Playbook 2026.

The post CISA Warns of Chromium Type Confusion 0-Day Vulnerability Actively Exploited in Attacks appeared first on Cyber Security News.