NG Solution Team
Cybersecurity

Chrome fixes actively exploited V8 zero-day (CVE-2026-85046)

Google has released a Chrome security update that patches 12 vulnerabilities, including a high-severity V8 flaw tracked as CVE-2026-85046 that is being actively exploited in the wild. The fixes are included in Chrome 152.0.7977.82/.83 for Windows and macOS and version 152.0.7977.82 for Linux, and are being deployed gradually.

Chrome is built on the Chromium open-source project, which also underpins Microsoft Edge, Brave and Opera.

Chrome update details and affected versions

Users should install the update promptly by opening Settings → About Chrome, allowing the browser to check for and download the latest release, and then restarting Chrome to activate the fixes. Because CVE-2026-85046 is already being exploited, users should not delay restarting after installing the update.

Chrome V8 type confusion and potential impact

CVE-2026-85046 is described as a type confusion issue in V8, Chrome’s JavaScript and WebAssembly engine. Security researcher Salvatore Gulizia (aka Serotav) reported the bug to Google on August 4, and Google disclosed the fixes in a September 3 Chrome Stable Channel bulletin. The company said it is aware of an exploit being used in the wild but did not share technical details about the attacks or identify who is exploiting the vulnerability.

Type confusion vulnerabilities occur when software treats an object as a different type than it actually is; in a JavaScript engine such as V8 this can cause incorrect memory access and potentially allow an attacker to read or modify memory. In practice, exploitation could begin when a victim visits a malicious or compromised webpage containing specially crafted JavaScript. Depending on the exact nature of the flaw and the browser’s security boundaries, an attacker could attempt to corrupt memory and achieve code execution inside Chrome’s renderer process. Google has not disclosed whether CVE-2026-85046 has been chained with other flaws in observed attacks.

Other fixes and disclosure restrictions

The update also resolves nine other high-severity vulnerabilities affecting components including CrashReporting, Network, Compositing, WebGL, CacheStorage, DevTools and Skia; these include several use-after-free and out-of-bounds memory flaws, as well as another V8 issue involving a race condition. Two medium-severity vulnerabilities were also corrected. Google is temporarily restricting access to detailed bug reports for some vulnerabilities until most Chrome users have received the update, a standard measure intended to reduce information available to attackers while systems remain exposed.

Related posts

Nigerian Army Confirms Attempted Cyberattack on X Account

Michael Johnson

Has OpenAI confirmed its AI escaped a sandbox and hacked Hugging Face?

Michael Johnson

Datadog Falls 22% in a Month After Large Customer Cut Dampens Outlook

James Smith

This website uses cookies to improve your experience. We assume you agree, but you can opt out if you wish. Accept More Info

Privacy & Cookies Policy