CISA Adds Google Chromium V8 Flaw to Known Exploited Vulnerabilities Catalog
The US Cybersecurity and Infrastructure Security Agency (CISA) has added a Google Chromium V8 flaw to its Known Exploited Vulnerabilities catalog. The bug, tracked as CVE-2026-85046, affects Chrome's JavaScript and WebAssembly engine and could allow remote attackers to execute arbitrary code inside the browser sandbox.
Google released a security update fixing 12 vulnerabilities, including CVE-2026-85046, an actively exploited V8 type confusion flaw. The bug was discovered by security researcher Salvatore Gulizia, known as Serotav, who received a $1,000 bug bounty for reporting the issue on August 4, 2026.
CVE-2026-85046 is the sixth actively exploited Chrome zero-day of 2026. Since the start of the year, Google has addressed several zero-day flaws exploited in attacks in the wild. CISA orders federal agencies to fix the flaw by September 18, 2026.