Google and Opera: CISA Warns of Chromium Type Confusion 0-Day Vulnerability Actively Exploited in Attacks

Google and Opera: CISA Warns of Chromium Type Confusion 0-Day Vulnerability Actively Exploited in Attacks

Critical Chromium V8 Vulnerability (CVE-2026-85046) Actively Exploited, Added to CISA’s KEV Catalog

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added CVE-2026-85046, a critical type confusion vulnerability in Google’s Chromium V8 JavaScript engine, to its Known Exploited Vulnerabilities (KEV) Catalog after confirming active exploitation in the wild. The flaw, classified under CWE-843, arises from incorrect handling of object types, allowing attackers to manipulate memory and potentially execute arbitrary code within a browser’s sandbox.

Exploitation requires tricking a user into visiting a maliciously crafted HTML page, which could lead to credential theft, malicious downloads, or further compromise. While browser sandboxing limits the immediate impact, successful exploitation still poses significant risks, including surveillance and follow-on attacks.

The vulnerability affects Chromium-based browsers, including Google Chrome, Microsoft Edge, and Opera, depending on their V8 and Chromium versions. Google has released a Stable Channel update for Chrome desktop users, but organizations must verify patches across all managed browsers patching Chrome alone may not fully mitigate exposure.

CISA’s inclusion in the KEV Catalog underscores the urgency, though details on whether the flaw has been used in ransomware campaigns remain undisclosed. Under Binding Operational Directive 22-04, federal agencies must apply vendor-recommended mitigations or discontinue use of affected products if patches are unavailable.

Security teams are advised to prioritize updates, enable automatic browser updates, and monitor for suspicious activity, particularly on endpoints accessing cloud portals, email, or SaaS platforms. Additional measures, such as restricting browser extensions and enforcing phishing-resistant MFA, can help reduce potential damage.

Source: https://cybersecuritynews.com/chromium-type-confusion-0-day-vulnerability/

Google TPRM report: https://www.rankiteo.com/company/googlellc

Opera TPRM report: https://www.rankiteo.com/company/operation-medical

"id": "opegoo1788892236",
"linkid": "operation-medical, googlellc",
"type": "Vulnerability",
"date": "9/2026",
"severity": "85",
"impact": "4",
"explanation": "Attack with significant impact with customers data leaks"
{'affected_entities': [{'customers_affected': 'All users of affected versions',
                        'industry': 'Technology',
                        'location': 'Global',
                        'name': 'Google Chrome',
                        'type': 'Browser'},
                       {'customers_affected': 'All users of affected versions',
                        'industry': 'Technology',
                        'location': 'Global',
                        'name': 'Microsoft Edge',
                        'type': 'Browser'},
                       {'customers_affected': 'All users of affected versions',
                        'industry': 'Technology',
                        'location': 'Global',
                        'name': 'Opera',
                        'type': 'Browser'}],
 'attack_vector': 'Malicious HTML page (phishing/social engineering)',
 'data_breach': {'sensitivity_of_data': 'High (credentials, potential for PII)',
                 'type_of_data_compromised': ['Credentials',
                                              'Potential for other sensitive '
                                              'data']},
 'description': 'CISA has added CVE-2026-85046, a critical type confusion '
                'vulnerability in Google’s Chromium V8 JavaScript engine, to '
                'its Known Exploited Vulnerabilities (KEV) Catalog after '
                'confirming active exploitation in the wild. The flaw allows '
                'attackers to manipulate memory and potentially execute '
                'arbitrary code within a browser’s sandbox. Exploitation '
                'requires tricking a user into visiting a maliciously crafted '
                'HTML page, leading to credential theft, malicious downloads, '
                'or further compromise.',
 'impact': {'data_compromised': ['Credentials',
                                 'Potential for data exfiltration'],
            'identity_theft_risk': 'High (credential theft)',
            'operational_impact': 'Potential for surveillance and follow-on '
                                  'attacks',
            'systems_affected': 'Chromium-based browsers (Google Chrome, '
                                'Microsoft Edge, Opera)'},
 'investigation_status': 'Ongoing',
 'post_incident_analysis': {'corrective_actions': 'Patch management, enhanced '
                                                  'monitoring, MFA enforcement',
                            'root_causes': 'Incorrect handling of object types '
                                           'in Chromium V8 JavaScript engine '
                                           '(CWE-843)'},
 'recommendations': ['Prioritize updates for Chromium-based browsers',
                     'Enable automatic browser updates',
                     'Monitor for suspicious activity on endpoints',
                     'Restrict browser extensions',
                     'Enforce phishing-resistant MFA'],
 'references': [{'source': 'CISA Known Exploited Vulnerabilities Catalog'}],
 'regulatory_compliance': {'regulatory_notifications': 'CISA KEV Catalog '
                                                       'inclusion (Binding '
                                                       'Operational Directive '
                                                       '22-04 for federal '
                                                       'agencies)'},
 'response': {'containment_measures': 'Apply vendor-recommended patches, '
                                      'enable automatic browser updates',
              'enhanced_monitoring': 'Monitor for suspicious activity on '
                                     'endpoints accessing cloud portals, '
                                     'email, or SaaS platforms',
              'remediation_measures': 'Patch affected Chromium-based browsers, '
                                      'restrict browser extensions, enforce '
                                      'phishing-resistant MFA'},
 'title': 'Critical Chromium V8 Vulnerability (CVE-2026-85046) Actively '
          'Exploited',
 'type': 'Type Confusion Vulnerability',
 'vulnerability_exploited': 'CVE-2026-85046 (CWE-843)'}
Great! Next, complete checkout for full access to Rankiteo Blog.
Welcome back! You've successfully signed in.
You've successfully subscribed to Rankiteo Blog.
Success! Your account is fully activated, you now have access to all content.
Success! Your billing info has been updated.
Your billing was not updated.