Cybersecurity
Google patches Chrome zero-day used in attacks
Google rolled out a Chrome update for CVE-2026-85046, a type-confusion bug in V8 that it said had an exploit in the wild, while also fixing 11 other vulnerabilities.
- Google updated Chrome to versions 152.0.7977.82/.83 on Windows and macOS and 152.0.7977.82 on Linux in a gradual rollout.
- The update fixed CVE-2026-85046 and 11 other vulnerabilities.
- Google said it knew of an exploit for CVE-2026-85046 in the wild.
- Salvatore Gulizia, known online as Serotav, reported the issue to Google.
- Google said CVE-2026-85046 was the sixth Chrome bug it had fixed that had been actively exploited since the start of the year.
Google updated Chrome to versions 152.0.7977.82/.83 on Windows and macOS and 152.0.7977.82 on Linux, and said the rollout would reach users gradually. The update fixed CVE-2026-85046, which the company described as a type-confusion flaw, along with 11 other vulnerabilities.
Google said it was aware of an exploit for CVE-2026-85046 in the wild, but it did not publish technical details. The company said that withholding information was meant to give users and dependent projects time to apply the fix.
Salvatore Gulizia, who is also known online as Serotav, reported the flaw to Google. The company said V8, Chrome’s open-source JavaScript and WebAssembly engine, was the affected component.
Google said the issue might be triggered by a specially crafted HTML page with malicious JavaScript and could lead to remote code execution inside Chrome’s sandboxed renderer process. It also said the update fixed nine other high-severity problems across Crash Reporting, Network, Compositing, WebGL, CacheStorage, DevTools, Skia and a race condition in V8.
Google said CVE-2026-85046 was the sixth actively exploited Chrome bug it had fixed since the start of the year. It advised users to let the update arrive through Chrome’s settings page, then restart the browser, and said the same approach was advisable for Chrome-based browsers including Microsoft Edge, Brave, Opera and Vivaldi.
Named in this story
People
- Salvatore Gulizia
- reported the flaw to Google
Companies
- updated Chrome and issued the advisory
Products and systems
- Chrome
- the browser Google patched
- CVE-2026-85046
- the zero-day flaw Google fixed
- V8
- the engine where the flaw was found
- Microsoft Edge
- one of the Chrome-based browsers advised to update
- Brave
- one of the Chrome-based browsers advised to update
- Opera
- one of the Chrome-based browsers advised to update
- Vivaldi
- one of the Chrome-based browsers advised to update
How the source tells it
The piece read as a plain security update, with urgency coming from active-exploitation language and advice to patch promptly.
- urgency active-exploitation framing and immediate-update guidance
- threat a live exploit and possible remote code execution are stressed before technical detail