Google security advisory (AV26-883) – Update 1

Used in attacksCriticalCanadian Centre for Cyber Security · Canadian Centre for Cyber Security·

At a glance

Severity
Critical
Used in attacks
Yes, 1 of 1 flaw named
Flaws named
CVE-2026-85046
Vendors and products
GoogleChrome
Industries
Government
Reported by
1 outlet

As of September 3, 2026, Google is affected by vulnerabilities in the following product:

  • Chrome
    • Prior to 152.0.7977.82

Google is aware that an exploit for CVE-2026-85046 exists in the wild.

Update 1

On September 4, 2026, Cybersecurity and Infrastructure Security Agency (CISA) added CVE-2026-85046 to their Known Exploited Vulnerabilities (KEV) Database.

The Cyber Centre encourages users and administrators to review the provided web links and apply any necessary updates as they become available.

Reproduced in full under licence from Canadian Centre for Cyber Security. © Canadian Centre for Cyber Security. Written by Canadian Centre for Cyber Security.

Vulnerabilities referenced

  • Google Chromium V8

    Google Chromium V8 contains a type confusion vulnerability that allows a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. This vulnerability could affect multiple web browsers that utilize Chromium, including, but not limited to, Google Chrome, Microsoft Edge, and Opera.

    Used in attacks

    Added to CISA's list 2026-09-04 · Exploit code published · Patch or advisory available

    Full record →

Coverage

One outlet has carried this so far.

  1. Canadian Centre for Cyber SecurityOfficial SourceFirst reported

    2026-09-04 17:21 UTC

Related stories