CISA Adds new exploited Google Chrome flaw to its watch list
CISA has added a new security flaw in Google’s Chromium browser to its list of actively exploited vulnerabilities, according to a cybersecurity advisory. This means attackers are already using this specific weakness to compromise systems. That makes it a high priority for business owners to address.
CISA has added a new security flaw in Google’s Chromium browser to its list of actively exploited vulnerabilities, according to a cybersecurity advisory. This means attackers are already using this specific weakness to compromise systems. That makes it a high priority for business owners to address.
The agency tracked CVE-2026-85046, a Google Chromium V8 Type Confusion Vulnerability, to its Known Exploited Vulnerabilities (KEV) Catalog based on evidence of active exploitation. The KEV Catalog tracks vulnerabilities that threat actors are actively using to attack organizations, posing significant risks to federal and private sectors alike. (CISA)
While the directive BOD 26-04 requiring rapid remediation of KEV-listed flaws applies only to federal agencies, CISA encourages all organizations to adopt similar risk-based vulnerability management practices. Ignoring it could leave your office’s computers open to takeover by cybercriminals.
What to check this week
If you use Google Chrome or a tool built on that same Chromium engine, here’s what to do next.
- Check if your office computers use Google Chrome or any software built on the Chromium browser, as these are affected by CVE-2026-85046.
- Prioritize installing the latest security updates for Chromium-based browsers to close the gap that attackers are currently exploiting.
- Review your organization’s vulnerability management process to ensure you’re prioritizing patches for flaws listed in CISA’s KEV Catalog.
We’d rather you turned it on and complain about the extra step than ignored the alert. Ask whoever runs your IT whether this is already handled; it probably is. But if they haven’t checked the KEV list this week, they need to.
Sources: CISA Cybersecurity Advisories.
3DPrintStack
Stop losing money on underpriced jobs
Filament tracking, print queue, real cost per print, and a P&L that shows which jobs actually pay.
One plan · $20/month · 14-day free trial