The Cybersecurity and Infrastructure Security Agency (CISA) has added a significant vulnerability, tracked as CVE-2026-85046, to its Known Exploited Vulnerabilities Catalog. This critical flaw affects the V8 JavaScript and WebAssembly engine used by Chromium-based browsers. The vulnerability arises from type confusion, a condition where software misinterprets an object’s data type, potentially allowing attackers to execute arbitrary code.

CVE-2026-85046 can be exploited by remote attackers through a specially crafted HTML page, leading to code execution within the browser sandbox. Although sandboxing is a security measure, attackers can still exploit this to steal credentials, download malicious content, or conduct surveillance. This issue is particularly concerning because Chromium is the backbone for popular browsers like Google Chrome, Microsoft Edge, and Opera.

Organizations should not only focus on updating Google Chrome but also examine all Chromium-based browsers in use. CISA's inclusion of this vulnerability in its catalog highlights its active exploitation status. Although the agency has not confirmed its use in ransomware attacks, the risk remains significant. Google has issued a Stable Channel update for Chrome users, which should be deployed swiftly through enterprise update management systems.

Security teams are urged to ensure automatic updates are enabled, identify devices running outdated software, and monitor for suspicious web activity. The vulnerability's impact extends beyond patching, as browsers are often used to access critical resources like cloud services and corporate emails. To mitigate risks, organizations should restrict unnecessary browser extensions, enforce multi-factor authentication, and maintain robust endpoint detection.

CISA advises applying vendor-recommended mitigations or ceasing the use of affected products if mitigations are unavailable, following the guidance of Binding Operational Directive 26-04 for risk-based patching.