LIVE · cybersecurity feed
Live wire
Hackers Leak Millions of Airport Passenger Records After Ransom RefusalCVE-2026-14894 · Over 440,000 Exploit Attempts Target Super Forms and Elementor Pro RCE FlawsCisco searched for IOS XR bugs and found so many it rolled them into an update releaseAttackers exploit zero-days in consistently besieged SonicWall productIntroducing context-aware vulnerability discovery and remediation with Cloudflare Managed Defense and OpenAI Daybreak modelsHPE patches critical ArubaOS-CX remote code execution flawCVE-2026-82329 · Attackers Pounce on Critical Artifactory Flaw Following DisclosureCVE-2026-0768 · Critical Langflow flaw exploited to steal OpenAI and AWS keysCVE-2026-82329 · Attackers Exploit Critical JFrog Artifactory Flaw to Mint Admin Tokens Days After DisclosureCVE-2026-82329 · Critical JFrog Artifactory Vulnerability Reportedly Exploited in the Wild
CVE-2026-85046

U.S. CISA adds Google Chromium V8 flaw to its Known Exploited Vulnerabilities catalog

U.S. Cybersecurity and Infrastructure Security Agency (CISA) adds Google Chromium V8 flaw to its Known Exploited Vulnerabilities catalog. The U.S. Cybersecurity and Infrastructure Security Agency (CISA) added a Google Chromium V8 flaw, tracked as CVE-2026-85046 (CVSS score of 8,8), to its Known Exploited Vulnerabilities (KEV) catalog. This week, Google released a Chrome security update fixing 12 [

zeroday.news ·

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added a critical Google Chromium V8 vulnerability, identified as CVE-2026-85046, to its Known Exploited Vulnerabilities (KEV) catalog. This type confusion flaw, affecting Chrome's JavaScript and WebAssembly engine, has a CVSS score of 8.8 and is actively being exploited in the wild.

Google recently released a security update for Chrome, addressing a total of 12 vulnerabilities, including CVE-2026-85046. The flaw could allow a remote attacker to execute arbitrary code within the browser's sandbox by enticing a user to visit a specially crafted HTML page. Google has confirmed that an exploit for this vulnerability exists.

Security researcher Salvatore Gulizia, known as Serotav, reported the vulnerability on August 4, 2026, and received a $1,000 bug bounty. Serotav described the bug as a V8 compiler issue that causes an array with `PACKED_ELEMENTS` to incorrectly receive the `PACKED_SMI_ELEMENTS` map, which can be leveraged for arbitrary read/write operations on the JavaScript heap. The bug was present in both the Maglev and Turbofan compilers.

This marks the sixth actively exploited Chrome zero-day vulnerability addressed by Google in 2026. Previous zero-day flaws exploited in attacks this year include: CVE-2026-2441 (use-after-free in CSS) in February; CVE-2026-3909 (out-of-bounds write in Skia 2D graphics library) and CVE-2026-3910 (implementation flaw in the V8 JavaScript/WebAssembly engine) in March; CVE-2026-5281 (use-after-free in Dawn WebGPU component) in April; and CVE-2026-11645 (out-of-bounds memory access in the V8 JavaScript engine) in June. All these vulnerabilities also carried a CVSS score of 8.8.

Google has updated Chrome Stable to version 152.0.7977.82/.83 for Windows and Mac, and 152.0.7977.82 for Linux. The rollout of these updates is expected to occur over the coming days and weeks.

In accordance with CISA's Binding Operational Directive (BOD) 22-01, federal civilian executive branch (FCEB) agencies are mandated to address vulnerabilities listed in the KEV catalog by a specified due date to safeguard their networks. CISA has set a deadline of September 18, 2026, for federal agencies to fix CVE-2026-85046. Private organizations are also strongly advised to review the catalog and remediate these vulnerabilities within their own infrastructure.

vulnerabilitypatch
ShareXLinkedInWhatsAppFacebook

More News

view all →
ai

[Virtual Event] What Every Enterprise Should Know About Securing Cloud Assets in the Age of AI

ai

[Virtual Event] Building a Secure AI Strategy for the Enterprise

security

European parliament members call for slowdown of Serbia’s EU entry over spyware use

The letter follows revelations about Serbian student activists being infected with Pegasus and NoviSpy, and coincides with other pressures on Belgrade. The post European parliament members call for slowdown of Serbia’s EU entry over spyware use appeared first on CyberScoop.

security

Friday Squid Blogging: Squid on a Stick at the New York State Fair

Looks tasty. As usual, you can also use this squid post to talk about the security stories in the news that I haven’t covered. Blog moderation policy.

phishing

ASCII smuggling isn't just an AI security risk

Phishers find a new use for invisible Unicode tag characters

ai

How to secure edge AI in customer-owned environments

As AI moves into customer-owned environments, organizations need new ways to verify the systems, software, and AI assets they trust before releasing sensitive data, credentials, and models. The post How to secure edge AI in customer-owned environments appeared first on Microsoft Security Blog.