Exploited Known exploited (KEV) CVE-2026-85046

One component inside several browsers: type confusion in Chromium V8

Google Chromium V8 Added to KEV Sep 4, 2026 Federal remediation due 2026-09-18

A type confusion flaw added to the catalog on 4 September 2026. The record itself states that it could affect multiple Chromium-based browsers, naming Chrome, Edge and Opera.

Key facts

  • CVE IDCVE-2026-85046
  • Affected (vendor / product)Google Chromium V8
  • CWECWE-843
  • ExploitationListed in CISA KEV (exploitation confirmed)
  • Remediation due2026-09-18 (U.S. federal civilian agencies, BOD 22-01)

Key points

  • A type confusion vulnerability in V8, the JavaScript engine in Chromium, reachable through a crafted HTML page.
  • The record itself states the flaw could affect several Chromium-based browsers, naming Chrome, Edge and Opera.
  • V8 appears 40 times in the catalog, and 20 of those are the same weakness, CWE-843.
  • The required action cites BOD 26-04 and forensics triage requirements rather than the usual BOD 22-01 text.

1A record listed under the name of a component

In the previous article the product field grouped several operating systems. Here it names Chromium V8 — not a browser but the JavaScript engine that runs inside one.

Times V8 appears40third most of any product
Of those, type confusion (CWE-843)20exactly half
Window on this record14 daysadded 4 September 2026, due 18 September

The description states for itself that the reach extends beyond Chrome, to browsers built on Chromium including Microsoft Edge and Opera. Anyone searching by the name of the browser they use will not find this record.

2Half of them are the same type

Twenty of V8's 40 entries are type confusion (CWE-843), a defect in which a value is handled as a type it is not. It recurs in systems where types are settled at run time, as in a JavaScript engine.

Type confusion (CWE-843)20 / 40
Out-of-bounds write (CWE-787)10 / 40
Heap-based buffer overflow (CWE-122)8 / 40
Out-of-bounds read (CWE-125)4 / 40

That contrasts with the 172 Windows entries, which scattered across many types. The narrower the role of a component, the narrower the range of defects found in it.

3The required action is worded differently

The remediation instruction on this record departs from the usual text. Most records say to apply mitigations per vendor instructions and follow BOD 22-01 guidance for cloud services. This one requires compliance with BOD 26-04, prioritizing security updates based on risk, and with forensics triage requirements, and the references carry URLs for both documents.

The next article takes up a record that asks for discontinuation rather than an update.

Why it matters

Tracking vulnerabilities by browser name misses records filed under the underlying component. Know what your browsers are built on and track by component name as well.

FAQ

What is type confusion?
A defect in which a value is handled as a different type from what it actually is. It recurs in systems where types are settled at run time.
Is this irrelevant if I do not use Chrome?
The record states it could affect multiple Chromium-based browsers, so Edge, Opera and others built on the same base are in scope.
Is execution inside the sandbox limited in impact?
The record describes arbitrary code execution inside the sandbox. That does not rule out combination with other defects.

Sources (primary)

This article is an independent organization based on the U.S. official data below. Always verify the exact, latest details and applicability with the official and vendor sources.

#KEV#Known exploited#Chromium#Type confusion#Vulnerability management
Disclaimer: This site independently summarizes and classifies information based on official data sources. Always verify the latest and accurate information with the official sources. Content on finance, health, legal, and security is information, not advice. This site is not an official website of the U.S. government.