Google Patches Actively Exploited Chrome Zero-Day CVE-2026-85046

Google has issued security updates addressing twelve vulnerabilities in the Chrome browser, including an actively exploited zero-day flaw cataloged as CVE-2026-85046.

The high-severity vulnerability carries a CVSS score of 8.8 and involves a type confusion bug within V8, Chrome’s core JavaScript and WebAssembly engine. According to technical advisories, the defect enables remote attackers to execute arbitrary code within the browser sandbox via specially crafted HTML pages.

Google confirmed the active exploitation of the bug in a security advisory published on Thursday. “Google is aware that an exploit for CVE-2026-85046 exists in the wild,” the company stated, while withholding detailed telemetry regarding the ongoing attacks.

Security researcher Salvatore Gulizia, also known as Serotav, discovered and reported the vulnerability on August 4, 2026. Gulizia received a $1,000 bug bounty reward for the disclosure and later detailed the root cause in a technical write-up, explaining that the issue stems from compiler behaviors in V8 that cause an array containing PACKED_ELEMENTS to incorrectly receive the map PACKED_SMI_ELEMENTS, leading to arbitrary read and write capabilities on the JavaScript heap.

To mitigate the risk posed by CVE-2026-85046, users must update their software immediately. Google has shipped the fixes in Chrome version 152.0.7977.82 and .83 for Windows and macOS, and version 152.0.7977.82 for Linux, with broad availability rolling out across ecosystems over the coming days.

This vulnerability marks the sixth zero-day flaw patched by Google in the Chrome browser throughout 2026. Prior patches this year addressed actively exploited issues including CVE-2026-2441, CVE-2026-3909, CVE-2026-3910, CVE-2026-5281, and CVE-2026-11645.

Leave a Reply

Your email address will not be published. Required fields are marked *