Google shipped an out-of-band security update for its Chrome browser on September 4, 2026, closing a zero-day vulnerability that is already being exploited in the wild. Tracked as CVE-2026-85046, the flaw sits in the V8 JavaScript engine and marks the sixth exploited Chrome zero-day of the year.
Type confusion in V8, rated CVSS 8.8
According to the Google Chrome Releases blog, the issue is a type-confusion bug: the engine misinterprets one object type as another, allowing memory to be corrupted. A crafted HTML page can then be used to execute arbitrary code inside the browser sandbox. The flaw carries a CVSS score of 8.8, rated high. Technically it stems from a compiler bug that enables improper mapping of array elements on the JavaScript heap.
An exploit is already circulating
Google confirms that an exploit for CVE-2026-85046 exists in the wild. The company withheld further details about the attacks to give users and dependent projects time to apply the patch. The vulnerability was reported on August 4, 2026, by security researcher Salvatore Gulizia (aka Serotav), who received a $1,000 bug bounty.
The fix is included in the Stable channel. Affected users should update immediately:
- Windows and macOS: Chrome 152.0.7977.82/.83
- Linux: Chrome 152.0.7977.82
Because Chromium-based browsers such as Microsoft Edge, Brave, Vivaldi and Opera share the same engine, their vendors are expected to roll out updates shortly as well. Chrome typically updates itself automatically; opening “About Google Chrome” and relaunching forces the installation.
Sources: Google Chrome Releases · Help Net Security · BleepingComputer · CISA KEV



















