The Cybersecurity and Infrastructure Security Agency (CISA) mandated federal agencies and critical infrastructure operators to apply mitigations for the Google Chromium V8 vulnerability CVE-2026-85046 by September 18, 2026. This requirement was issued under Binding Operational Directive 26-04, which governs how stakeholders must address known exploited vulnerabilities in their systems.
The vulnerability allows a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. Security researcher Salvatore Gulizia discovered the type confusion in V8 bug that constitutes CVE-2026-85046. The flaw is classified under CWE-843, indicating a specific category of software weakness related to type confusion.
The vulnerability affects web browsers utilizing Chromium, including Google Chrome, Microsoft Edge, and Opera. Google Chrome is a web browser developed by Google that relies on the V8 JavaScript engine. Operators of these browsers must evaluate the risk posed by this specific security defect to their networks.
Stakeholders must discontinue use of the product if mitigations are unavailable. This directive ensures that systems remain secure even when immediate patching is not possible through standard update channels. Organizations are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
Mitigations must be applied in accordance with vendor instructions and CISA’s BOD 26-04 guidance. Forensic triage is not required for CVE-2026-85046, simplifying the response process for affected entities. Known ransomware campaign use of CVE-2026-85046 is unknown, though the potential for exploitation remains a priority for federal defenders.
Google released Chrome version 152.0.7977.75/.76 for Windows and macOS and version 152.0.7977.75 for Linux with fixes for 26 bugs. Two critical-severity vulnerabilities in Chrome 152 are use-after-free issues in Shared Tab Groups (CVE-2026-84353) and WebGL (CVE-2026-84352). The Chrome 152 update addresses nine high-severity security defects, including use-after-free, incorrect authorization, information leak, improper input validation, uninitialized resource, and buffer overflow weaknesses.
Fifteen vulnerabilities in the Chrome 152 update are classified as medium- and low-severity issues. Three of the flaws fixed in Chrome 152 were reported by external researchers. These updates provide the necessary patches to resolve the underlying code errors that could lead to exploitation.
Mozilla released Firefox 155 with patches for 29 security defects. Thirteen high-severity issues in Firefox 155 involve use-after-free, sandbox escape, and memory corruption. The Firefox 155 vulnerabilities were addressed in GC, Navigation, Audio/Video, Security, WebGPU, Core & HTML, and Grid components, and in Firefox for Android.
Mozilla released Firefox ESR 115.40, Firefox ESR 140.15, Firefox ESR 153.2, Thunderbird 155, Thunderbird 140.15, and Thunderbird 153.2 with fixes for these vulnerabilities. These releases ensure that users of extended support versions and email clients also receive protection against similar classes of security defects.
Timeline
CVE-2026-85046 is a type confusion vulnerability in Google Chromium V8 classified under CWE-843. CISA added CVE-2026-85046 to its catalog on September 4, 2026. CISA requires applying mitigations for the Google Chromium V8 vulnerability CVE-2026-85046 by September 18, 2026.
Why It Matters
The mandate shows the ongoing risk posed by type confusion vulnerabilities in widely used web browsers. By requiring mitigation by a specific date, CISA aims to reduce the window of opportunity for attackers who might exploit the flaw to execute arbitrary code. The directive applies to both federal agencies and critical infrastructure operators, reflecting the broad impact of Chromium-based browsers across essential services.
The absence of known ransomware campaigns using this specific vulnerability does not eliminate the threat, as the capability for remote code execution remains a high-priority target for adversaries. The requirement to discontinue use if mitigations are unavailable reflects the severity with which federal authorities view the potential for sandbox escapes. This action fits into a broader pattern of rapid response to vulnerabilities that affect multiple major software platforms, including those from Google and Mozilla.
forum Comments (0)
No comments yet. Be the first to comment.