Chrome/V8 zero-day attivamente sfruttato e inserito nel catalogo CISA KEV

Chrome/V8 zero-day actively exploited and added to the CISA KEV catalog

Google has released an urgent update for Chrome that fixes 12 vulnerabilities, including CVE-2026-85046, a type confusion flaw in the V8 engine already exploited in the wild. The flaw can allow a remote attacker to execute arbitrary code in the browser sandbox through a specially crafted HTML page. CISA has added the bug to the Known Exploited Vulnerabilities catalog, confirming that it is an issue that should be patched immediately. The flaw was reported on August 4 by researcher Salvatore Gulizia, who received a bounty, but Google did not disclose details about the exploitation campaigns. The news is important because Chrome is a universal target and a browser compromise can become the entry point for data theft, malware execution, or further lateral movement.

Source: Security Affairs

Leave a Reply

Your email address will not be published. Required fields are marked *


Post Comment