SPOJENO AI KEV ✓ (1 z 12) EPSS 0.01 (nejvyšší)
Google Chrome Stable Channel Update
Classification: Severe, Solution: Official Fix, Exploit Maturity: High, CVSSv3.1: None, CVEs: CVE-2026-85046, CVE-2026-85052, CVE-2026-85043, CVE-2026-85048, CVE-2026-85045, CVE-2026-85050, CVE-2026-85053, CVE-2026-85042, CVE-2026-85049, CVE-2026-85051, CVE-2026-85047, CVE-2026-85044, Summary: The Stable channel has been updated to 152.0.7977.82/.83 for Windows and Mac and 152.0.7977.82 for Linux, which will roll out over the coming days/weeks. A full list of changes in this build is available…
Microsoft Google veřejná správa FR FI CA NL US IT
CVE v události 12
| CVE | hodnocení | KEV | EPSS |
|---|---|---|---|
| CVE-2026-85042 | 9.6 3.1 · CISA-ADP | – | 0.00 |
| CVE-2026-85043 | 9.1 3.1 · CISA-ADP | – | 0.00 |
| CVE-2026-85044 | 6.5 3.1 · CISA-ADP | – | 0.00 |
| CVE-2026-85045 | 7.5 3.1 · CISA-ADP | – | 0.00 |
| CVE-2026-85046 | 8.8 3.1 · CISA-ADP | KEV ✓ | 0.01 |
| CVE-2026-85047 | 9.6 3.1 · CISA-ADP | – | 0.00 |
| CVE-2026-85048 | 8.3 3.1 · CISA-ADP | – | 0.00 |
| CVE-2026-85049 | 8.8 3.1 · CISA-ADP | – | 0.00 |
| CVE-2026-85050 | 9.6 3.1 · CISA-ADP | – | 0.00 |
| CVE-2026-85051 | 8.8 3.1 · CISA-ADP | – | 0.00 |
| CVE-2026-85052 | 3.1 3.1 · CISA-ADP | – | 0.00 |
| CVE-2026-85053 | 8.8 3.1 · CISA-ADP | – | 0.00 |
Hodnocení z katalogů, všechna, se stupnicí CVSS a vydavatelem. Rozpad vektoru je na stránce CVE.
Tahle CVE jsem vytáhl z širšího textu článku: CVE-2026-11645, CVE-2026-2441, CVE-2026-3909, CVE-2026-3910, CVE-2026-5281. Neukazuju u nich proto fakta z katalogů výše, a to preventivně, protože článek se na ně mohl jen odkazovat, třeba jako na starší kauzu.
Jak se o tom psalo 9
-
· CERT-FR – avis FR
Vulnérabilité dans Microsoft Edge (10 septembre 2026)
Une vulnérabilité a été découverte dans Microsoft Edge. Elle permet à un attaquant de provoquer une exécution de code arbitraire à distance. Microsoft indique que la vulnérabilité CVE-2026-85046 est activement exploitée.
-
· NCSC-FI FI nadpis události
Google Chrome Stable Channel Update
Classification: Severe, Solution: Official Fix, Exploit Maturity: High, CVSSv3.1: None, CVEs: CVE-2026-85046, CVE-2026-85052, CVE-2026-85043, CVE-2026-85048, CVE-2026-85045, CVE-2026-85050, CVE-2026-85053, CVE-2026-85042, CVE-2026-85049, CVE-2026-85051, CVE-2026-85047, CVE-2026-85044, Summary: The Stable channel has been updated to 152.0.7977.82/.83 for Windows and Mac and 152.0.7977.82 for Linux, which will roll out over the coming days/weeks. A full list of changes in this build is available…
-
· Cyber Centre Kanada CA
Google security advisory (AV26-883)
Serial Number: AV26-883Date: September 4, 2026 As of September 3, 2026, Google is affected by vulnerabilities in the following product: Chrome Prior to 152.0.7977.82 Google is aware that an exploit for CVE-2026-85046 exists in the wild. The Cyber Centre encourages users and administrators to review the provided web link and apply any necessary updates as they become available. Stable Channel Update for Desktop
-
· NCSC-NL NL
NCSC-2026-0341 [1.00] [M/H] Kwetsbaarheden verholpen in Google Chrome
Google heeft meerdere kwetsbaarheden verholpen in Google Chrome, specifiek in versies voor 152.0.7977.82. De kwetsbaarheden bevinden zich in verschillende componenten van Google Chrome, waaronder DevTools, Network, V8 JavaScript engine en Transactions Platform op iOS. Aanvallers kunnen deze kwetsbaarheden misbruiken door speciaal vervaardigde HTML-pagina's aan te bieden, wat kan leiden tot het uitvoeren van willekeurige code buiten de sandboxomgeving, het omzeilen van toegangsbeperkingen, het…
-
· CISA Advisories US
CISA Adds One Known Exploited Vulnerability to Catalog
CISA has added one new vulnerability to its Known Exploited Vulnerabilities (KEV) Catalog, based on evidence of active exploitation. CVE-2026-85046 Google Chromium V8 Type Confusion Vulnerability This type of vulnerability is a frequent attack vector for malicious cyber actors and poses significant risks to the federal enterprise. Binding Operational Directive (BOD) 26-04: Prioritizing Security Updates Based on Risk establishes vulnerability management requirements for Federal Civilian…
-
· BleepingComputer US
Google warns of new Chrome zero-day flaw exploited in attacks
Google has updated the Chrome browser to address an actively exploited high-severity zero-day flaw in the V8 engine and 11 other vulnerabilities. [...]
-
· CSIRT Itálie (ACN) IT
Google: rilevato sfruttamento di vulnerabilità zero-day in Chrome
Google ha rilasciato un aggiornamento per il browser Chrome al fine di correggere 12 nuove vulnerabilità di sicurezza, di cui 2 con gravità “critica” e 7 con gravità “alta”. Tra queste, si evidenzia lo sfruttamento attivo in rete della vulnerabilità zero-day CVE-2026-85046, che potrebbe consentire l’esecuzione di codice arbitrario sui dispositivi interessati.
-
· CISA KEV US
Google Chromium V8 Type Confusion Vulnerability (CVE-2026-85046)
CISA added CVE-2026-85046 to the Known Exploited Vulnerabilities catalog. Affected product: Google Chromium V8. Remediation due date: 2026-09-18.
-
· CERT-FR – avis FR
Multiples vulnérabilités dans Google Chrome (04 septembre 2026)
De multiples vulnérabilités ont été découvertes dans Google Chrome. Elles permettent à un attaquant de provoquer un problème de sécurité non spécifié par l'éditeur. Google indique que la vulnérabilité CVE-2026-85046 est activement exploitée.