Skip to content
Cybersecurity

Google Patches Actively Exploited Chrome Zero-Day CVE-2026-85046

Google Chrome security update patches actively exploited CVE-2026-85046 zero-day

Google has released a Chrome security update fixing 12 vulnerabilities, including a high-severity zero-day that the company says is already being exploited in the wild. The flaw, tracked as CVE-2026-85046, affects V8, Chrome’s engine for processing JavaScript and WebAssembly. The disclosure makes the update more urgent than a routine browser patch. Google has confirmed that an exploit for the vulnerability exists in the wild, although it has not released detailed information about the attacks while users are still being given time to install the fix.

Chrome zero-day affects V8

CVE-2026-85046 is classified as a type confusion vulnerability in V8. In simple terms, this kind of flaw can occur when software handles data as though it belongs to one type when it actually belongs to another, potentially creating an opening for attackers to manipulate how the browser processes memory. Google lists the vulnerability as high severity and credits security researcher Salvatore Gulizia, also known as Serotav, with reporting it on August 4. The company awarded a $1,000 bug bounty for the discovery. Security researchers report that a specially crafted HTML page can potentially be used to trigger the flaw and execute arbitrary code within Chrome’s sandbox. Google, however, has kept some technical details restricted while the security update rolls out.

Google fixes 12 Chrome vulnerabilities

CVE-2026-85046 was one of 12 security issues addressed in Chrome’s September 3 desktop update. The stable release moves Chrome to version 152.0.7977.82/.83 on Windows and Mac, while Linux receives version 152.0.7977.82. Google said the update would roll out over the coming days and weeks. The remaining vulnerabilities include another high-severity issue, CVE-2026-85052, involving an out-of-bounds read in Chrome’s crash-reporting component, along with several medium-severity flaws. Google has not publicly identified the attackers behind the exploitation of CVE-2026-85046. It has also not disclosed the full details of the attacks, including how widely the exploit has been used.

Users should update Chrome

For Chrome users, the immediate step is straightforward: install the latest available security update and restart the browser when prompted. Because Google has confirmed active exploitation, leaving an older version installed creates an avoidable security risk. The update is particularly relevant for organisations where Chrome is widely deployed across employee devices. A browser vulnerability can become an entry point for attacks simply because web browsers routinely process content from websites and online services.

Google has also continued to restrict technical information about the flaw until a larger share of users have received the patch. That is a common approach for actively exploited vulnerabilities, as releasing detailed exploitation information too early could make it easier for additional attackers to reproduce the problem. CVE-2026-85046 is also notable because it is the sixth actively exploited Chrome zero-day patched by Google in 2026, according to security researchers tracking the browser's security disclosures. For users, the message is less complicated than the vulnerability itself: Chrome has a fix, and updating is the most direct way to protect systems from a flaw that Google already knows attackers are using.