Advisories
CISA Adds New Chromium V8 Type‑Confusion CVE to KEV Catalog
CISA has incorporated CVE‑2026‑85046, a type‑confusion bug in Google Chromium’s V8 engine, into its Known Exploited Vulnerabilities list after confirmed active exploitation. The move reinforces the agency’s BOD 26‑04 mandate for rapid patching of high‑risk flaws on publicly exposed assets. Federal agencies must now prioritize remediation, while all entities are urged to adopt a risk‑based approach to vulnerability management.
What’s New?
CISA’s latest update to the KEV Catalog adds CVE‑2026‑85046, a type‑confusion vulnerability that can let attackers execute arbitrary code within the Google Chromium V8 JavaScript engine. The flaw has already been seen in the wild, prompting the agency’s inclusion of the CVE in the high‑risk list.
Why It Matters
Type‑confusion bugs are notorious for enabling attackers to bypass type checks, often leading to full system compromise. With Chromium powering a large portion of web browsers and embedded systems, the impact of this flaw is far‑reaching. The KEV designation signals that the vulnerability is actively exploited and that patching should be a top priority.
Federal Guidance
Under Binding Operational Directive 26‑04, federal civilian agencies are required to:
- Prioritize rapid remediation of KEV-listed CVEs on exposed assets that could grant total control post‑exploitation.
- Assess whether a system has been compromised before applying a patch.
- Defer action on lower‑risk CVEs until the high‑risk ones are addressed.
"The KEV Catalog is a critical tool for risk‑based vulnerability management, and agencies must act swiftly on high‑risk vulnerabilities…" – BOD 26‑04
Next Steps
Federal agencies should check their asset inventories for exposed Chromium components, apply the latest patches, and monitor for signs of exploitation. All organizations are encouraged to adopt a similar risk‑based approach and can submit additional exploited CVEs to CISA via the KEV Nomination Form.