← Terug naar overzicht

A type confusion vulnerability exists in Google Chromium's V8 JavaScript engine, tracked as CVE-2026-85046. The flaw allows a remote attacker to execute arbitrary code within the sandbox by luring a victim to a crafted HTML page. The vulnerability is particularly concerning as it impacts multiple Chromium-based browsers including Google Chrome, Microsoft Edge, and Opera. CISA has flagged this vulnerability under BOD 26-04, which prioritizes security updates based on risk. Forensic triage requirements have also been outlined in CISA's BOD 26-04 implementation guidance. The vulnerability is listed in the NVD and has been addressed in a Chrome stable channel update released in September 2026. Given its remote exploitability and broad browser impact, it is rated as high severity.

Affected products

  • Google Chrome
  • Google Chromium V8
  • Microsoft Edge
  • Opera

Related CVE's

  • CVE-2026-85046

Categories

  • Web Technologies
  • Zero-Day Vulnerabilities