โ† Back to Feed

Google Releases Chrome Update to Patch Actively Exploited V8 Zero-Day

CVE-2026-85046

September 4, 2026 ยท The Hacker News ยท Severity: CRITICAL

Google released security updates for 12 vulnerabilities, including CVE-2026-85046, a type confusion bug in V8 that is actively exploited in the wild. The flaw allows remote code execution inside Chrome's sandbox. Users are advised to update immediately. ๐Ÿ“Œ **Analyst Note:** The detailed disclosure by the researcher provides valuable insight into the bug mechanism, aiding defense development. The low bounty relative to impact suggests a need for stronger incentives in vulnerability research.

Google on Thursday released security updates to patch 12 vulnerabilities, including one that has come under active exploitation in the wild. The high-severity vulnerability, tracked as CVE-2026-85046 (CVSS score: 8.8), has been described as a type confusion bug in V8, Chrome's JavaScript and WebAssembly engine. "Type confusion in V8 in Google Chrome prior to 152.0.7977.82 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page," reads a description of the flaw in CVE.org. Security researcher Salvatore Gulizia (aka Serotav) has been credited with discovering and reporting the flaw on August 4, 2026. The researcher has been awarded a bug bounty of $1,000 for responsible disclosure. In a separate blog post detailing the issue, Gulizia  described it as a "V8 bug in the compilers that leads to an array containing PACKED_ELEMENTS to receive the map PACKED_SMI_ELEMENTS, this can be turned into arbitrary read/write on the JavaScript heap." As is usual in these cases, Google acknowledged that an "exploit for CVE-2026-85046 exists in the wild," but did not reveal any details about the nature of the attacks, or who is behind them. This is done to ensure that a majority of the users are updated with a fix and to prevent other threat actors from exploiting it. With the latest development, Google has addressed a total of six actively exploited Chrome zero-days since the start of the year. This includes CVE-2026-2441 , CVE-2026-3909, CVE-2026-3910 , CVE-2026-5281 , and CVE-2026-11645 . For optimal protection, users are advised to update their Chrome browser to versions 152.0.7977.82/.83 for Windows and Apple macOS, and 152.0.7977.82 for Linux. To make sure the latest updates are installed, users can navigate to More > Help > About Google Chrome and select Relaunch. Users of other Chromium-based browsers, such as Microsoft Edge, Brave, Opera, and Vivaldi, are also advised to apply the fixes as and when they become available. Update The U.S. Cybersecurity and Infrastructure Security Agency (CISA), on September 4, 2026, added CVE-2026-85046 to its Known Exploited Vulnerabilities ( KEV ) catalog, requiring Federal Civilian Executive Branch (FCEB) agencies to apply the patches by September 18, 2026. Found this article interesting? Follow us on Google News , Twitter and LinkedIn to read more exclusive content we post.

Key Takeaways

  • CVE-2026-85046 is a type confusion bug in Chrome's V8 engine that allows remote attackers to execute arbitrary code inside the sandbox using a crafted HTML page, with active exploitation confirmed.
  • Security researcher Salvatore Gulizia discovered and reported the flaw on August 4, 2026, receiving a $1,000 bug bounty for responsible disclosure to Google.
  • Google has addressed six actively exploited Chrome zero-days in 2026 and urges all users to update to version 152.0.7977.82 for Windows, macOS, or Linux.
โ˜• Buy a Coffee