Google has released a security update for Chrome that fixes a high-severity zero-day vulnerability actively exploited in the wild, along with 11 other security flaws in the browser’s V8 JavaScript engine and related components.
Tracked as CVE-2026-85046, the actively exploited vulnerability is a type confusion flaw. Google credited security researcher Salvatore Gulizia, also known online as “Serotav,” for reporting the issue.
The Chrome security update is being distributed gradually as version 152.0.7977.82/.83 for Windows and macOS, and version 152.0.7977.82 for Linux.
“Google is aware that an exploit for CVE-2026-85046 exists in the wild,” Google said in its Chrome release announcement.
The company has not released technical details or information about the exploit chain. Limiting these details gives Chrome users, developers, and projects based on Chromium more time to install the security update.
A type confusion vulnerability occurs when software incorrectly treats an object as a different data type. This can lead to memory corruption and may allow attackers to execute arbitrary code.
Chrome’s V8 engine is an open-source JavaScript and WebAssembly engine that compiles and runs code used by websites and web applications.
As a result, CVE-2026-85046 could potentially be triggered by a specially crafted HTML page containing malicious JavaScript. Successful exploitation could allow remote code execution inside Chrome’s sandboxed renderer process.
The Chrome update also fixes nine other high-severity vulnerabilities, including use-after-free and out-of-bounds memory flaws affecting Crash Reporting, Network, Compositing, WebGL, CacheStorage, DevTools, and Skia. The release also addresses race-condition vulnerabilities in V8.
CVE-2026-85046 is the sixth actively exploited Chrome vulnerability that Google has patched since the beginning of 2026. Previous Chrome zero-day fixes include:
- An out-of-bounds read and write vulnerability, tracked as CVE-2026-11645, in Chrome’s V8 JavaScript engine. The flaw was exploited in the wild and patched in June.
- An iterator-disabling vulnerability, tracked as CVE-2026-2441, in Chrome’s CSS font feature values implementation, CSSFontFeatureValuesMap. Google fixed the issue in mid-February.
- Two Chrome zero-day vulnerabilities exploited in a March attack campaign: an out-of-bounds write flaw in the Skia 2D graphics library, tracked as CVE-2026-3909, and an improper implementation vulnerability in the V8 JavaScript and WebAssembly engine, tracked as CVE-2026-3910.
- A use-after-free vulnerability, tracked as CVE-2026-5281, in Dawn, Chromium’s cross-platform implementation of the WebGPU standard. Google patched the flaw in April.
Chrome users should install the latest update as soon as it becomes available. To check for updates, open Chrome and go to Settings > About Chrome. The browser will automatically check for, download, and install available updates.
After the update finishes installing, restart Chrome to apply the security fixes. Because the vulnerability is being exploited in real-world attacks, users should avoid delaying the browser restart.
Users of Chromium-based browsers, including Microsoft Edge, Brave, Opera, and Vivaldi, should also install the latest available updates. Security patches may take several additional days to reach these browsers.
The overall prevention score can hide what happens after the initial access. If an attacker uses valid credentials, your defenses drop dramatically.
The Blue Report 2026 measures defense techniques by technology across 338 million simulations run in customer production environments.
Source: www.bleepingcomputer.com



