Code Defence Cyber security

CISA adds Google Chrome V8 engine type confusion zero day CVE-2026-85046 to KEV catalog

Federal cybersecurity authorities have formally added a high-severity web browser vulnerability to the Known Exploited Vulnerabilities catalog. The addition follows verified threat telemetry showing threat actors weaponizing the flaw in drive-by download attack chains targeting corporate desktop endpoints.

The vulnerability, tracked as CVE-2026-85046, affects Google Chrome and Chromium-based web browsers. The defect involves a type confusion error inside the V8 JavaScript and WebAssembly engine handling dynamic memory allocations. Unauthenticated remote adversaries hosting malicious web pages can exploit the memory corruption bug to break browser sandbox boundaries and execute arbitrary code within target user contexts. CISA mandated federal civilian agency compliance under Binding Operational Directive 26-04 with a September 25 remediation deadline.

Subverting web browser execution engines creates immediate initial access and credential theft risks across corporate workstations. When web browser zero-day flaws are actively weaponized, unmonitored employee web browsing allows threat actors to compromise host endpoints, harvest active session cookies, and pivot into corporate cloud environments.

– Deploy Chrome browser release updates 152.0.7977.82/.83 immediately across all Windows, macOS, and Linux enterprise endpoints.

– Enforce strict web isolation policies and DNS filtering rules to intercept unverified external web navigation on corporate devices.

– Inspect endpoint process telemetry for unexpected child processes spawned by web browser renderer executables.

– Invalidate active cloud application session cookies across endpoints confirmed to have visited unverified external links.

Client application security depends on rapid zero-day patch deployment and strict browser process isolation to ensure enterprise endpoints remain protected against unauthenticated web drive-by exploitation. #CodeDefence #Google #Chrome #V8 #ZeroDay #CISA #KEV #EndpointSecurity
/

Scroll to Top