Category: CISA Advisories
Let me ask you something: Would you leave your office door unlocked after learning someone was already trying the handle?
Probably not.
Yet that is essentially what happens when a business keeps an outdated browser installed after Google confirms that attackers are exploiting a security flaw in the wild. On September 4, 2026, CISA added CVE-2026-85046 to its Known Exploited Vulnerabilities Catalog, giving organizations a clear warning: this is not a theoretical problem.
It is an active attack.
What is CVE-2026-85046?
CVE-2026-85046 is a high-severity type confusion vulnerability in Chromium’s V8 engine. V8 is the part of Chrome that processes JavaScript and WebAssembly content on websites.
“Type confusion” sounds technical, right? Here is the simple version:
Imagine asking someone to carry a box of paper, but the label mistakenly tells them it contains gasoline. They handle the box incorrectly because the system believes the contents are something else.
That is the basic danger with a type confusion flaw. The browser can misinterpret data, allowing an attacker to manipulate how the system processes it.
According to the National Vulnerability Database, a remote attacker can use a specially crafted HTML page to execute arbitrary code inside the Chrome browser sandbox.
The vulnerability is tracked as CWE-843, and Chromium rates it High severity. The listed CVSS 3.1 score is 8.8 out of 10.
And here is where it gets serious: Google is aware that an exploit for CVE-2026-85046 exists in the wild.
Why active exploitation changes the risk
A vulnerability may sit quietly for months while vendors develop a fix. That is not the situation here.
Attackers can potentially send or direct a user to a malicious webpage. The page may look ordinary. It could appear in a search result, arrive through a phishing message, or be linked from a compromised website.
You open it without thinking twice…
And just like that, the browser may process malicious code.
The vulnerability requires user interaction because someone generally has to visit the crafted page. But that does not make it harmless. Your employees browse the web every day to check email, research customers, access cloud applications, review invoices, and manage business operations.
One careless click can expose a workstation to an attack chain.
The initial code execution occurs inside Chrome’s sandbox, which is a protective boundary designed to limit what browser content can access. However, attackers often use browser vulnerabilities as a first step. They may attempt to escape the sandbox, steal information, install additional malware, or move deeper into the network.
That is why CISA places actively exploited vulnerabilities in the KEV catalog. The catalog helps organizations prioritize the flaws attackers are actually using: not just the ones that look dangerous on paper.
CISA’s remediation deadline is September 18
CISA added CVE-2026-85046 to the KEV catalog on September 4, 2026. The listed remediation due date is September 18, 2026.
For U.S. federal civilian agencies, the deadline is a mandatory remediation requirement. For small businesses, it should be treated as a strong indicator of urgency.
You have roughly two weeks from the catalog listing to identify vulnerable systems, apply updates, verify that updates succeeded, and investigate any devices that may already have been exposed.
CISA’s required action is to:
- Apply vendor mitigations according to vendor instructions.
- Follow CISA’s BOD 26-04 guidance for prioritizing security updates based on risk.
- Evaluate each asset’s internet exposure.
- Follow applicable cloud-services guidance.
- Use CISA’s forensic triage requirements when investigating potentially affected assets.
- Discontinue use of the product if effective mitigations are unavailable.
This is not a “patch it when convenient” recommendation.
Chrome versions that fix the flaw
Google released a stable-channel update on September 3, 2026.
The fixed versions are:
- Windows: Chrome 152.0.7977.82 or 152.0.7977.83
- macOS: Chrome 152.0.7977.82 or 152.0.7977.83
- Linux: Chrome 152.0.7977.82
Older Chrome versions should be treated as vulnerable.
You can review Google’s official Stable Channel Update for Desktop for the release details. The vulnerability was reported by Salvatore Gulizia, known as Serotav, and is associated with Chromium bug 542403045.

Do not forget Microsoft Edge, Opera, and other Chromium browsers
Here is another important point: Chrome is not the only browser your business may use.
Microsoft Edge, Opera, Brave, Vivaldi, and other browsers are built on Chromium or use Chromium components. That does not automatically mean every browser is affected in exactly the same way or has the same update schedule.
It does mean you should inventory them.
Check for:
- Microsoft Edge on Windows workstations
- Opera on shared or specialized computers
- Chromium-based browsers installed by individual employees
- Portable browser versions
- Browsers used to access accounting, healthcare, legal, or customer-management platforms
- Browsers installed on laptops that employees use from home
Each vendor must provide its own security update. Do not assume that updating Chrome automatically updates Edge or Opera.
What your business should do today
So, what can you do?
Start with the devices most exposed to the internet and the systems used to access sensitive data.
1. Update Chrome immediately
Open Chrome and go to:
Menu → Help → About Google Chrome
Chrome will check for updates automatically. Install the update and restart the browser when prompted.
Do not stop after the download completes. The browser may need to restart before the protection is active.
2. Verify the installed version
Confirm that Windows and macOS systems show version 152.0.7977.82, 152.0.7977.83, or later.
Linux systems should show 152.0.7977.82 or later.
Record the device name, user, operating system, browser, and installed version. A simple spreadsheet is better than assuming every machine updated correctly.
3. Enable automatic updates
Automatic updates help reduce the time between a vendor release and protection on your devices.
They are not a substitute for verification, though. Updates can fail because of:
- Devices being offline
- Users postponing restarts
- Limited permissions
- Conflicting software
- Old operating systems
- Browser policies that block updates
4. Inventory every Chromium-based browser
Ask your IT provider or internal administrator to identify Chrome, Edge, Opera, and other Chromium-based browsers across your network.
Pay special attention to laptops used by remote workers in St. Louis, St. Charles County, Chesterfield, Clayton, O’Fallon, the Metro East, and throughout Missouri. A laptop outside the office is still a business asset.
5. Investigate suspicious activity
If a user visited an unusual website, opened a suspicious link, or noticed browser crashes around the time of the alert, preserve relevant information before wiping or rebuilding the device.
Look for:
- Unusual browser crashes
- Unexpected pop-ups or redirects
- New browser extensions
- Unknown applications
- Unusual account logins
- Security alerts from endpoint protection
- High CPU or network activity
- Files created shortly after browsing a suspicious page
Do not assume that a quiet computer is a clean computer.
How small businesses can reduce browser risk
Browser patching is one part of a broader cybersecurity strategy.
Your business also benefits from centralized update management, endpoint protection, multifactor authentication, secure backups, phishing awareness, and network monitoring. Together, these controls create layers of protection so one missed update does not become a full business disruption.
At Platinum Web Services, we help small businesses build personalized IT security programs that include proactive patching, cybersecurity solutions, device management, and practical response planning.
That support is available 24/7. Our business hours are 24/7, because browser exploits, phishing attempts, and security incidents do not follow a nine-to-five schedule.
If you are unsure which browsers are installed across your business: or whether your updates completed successfully: contact Platinum Web Services. We can help you review your environment, prioritize exposed systems, and establish a safer update process.
Our office is located at:
7827 Town Square Ave, 104-1184
O’Fallon, MO 63368
The bottom line
CVE-2026-85046 is a high-severity Chromium V8 vulnerability that allows remote code execution through a crafted HTML page. Google has confirmed active exploitation, and CISA added the flaw to its Known Exploited Vulnerabilities Catalog on September 4, 2026.
Update Chrome now. Verify the version. Check Edge, Opera, and other Chromium-based browsers. Restart systems when required, and investigate devices that may have encountered suspicious web content.
Your browser may feel like a simple tool, but it is also one of the most common doors into your business.
Make sure that door is locked.


0 Comments