Google Releases Chrome Update to Patch Actively Exploited V8 Zero-Day

ExploitedCriticalThe Hacker News · info@thehackernews.com (The Hacker News)·

Google on Thursday released security updates to patch 12 vulnerabilities, including one that has come under active exploitation in the wild.

The high-severity vulnerability, tracked as CVE-2026-85046 (CVSS score: 8.8), has been described as a type confusion bug in V8, Chrome's JavaScript and WebAssembly engine.

"Type confusion in V8 in Google Chrome prior to 152.0.7977.82 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page," reads a description of the flaw in CVE.org.

Security researcher Salvatore Gulizia (aka Serotav) has been credited with discovering and reporting the flaw on August 4, 2026. The researcher has been awarded a bug bounty of $1,000 for responsible disclosure.

In a separate blog post detailing the issue, Gulizia described it as a "V8 bug in the compilers that leads to an array containing PACKED_ELEMENTS to receive the map PACKED_SMI_ELEMENTS, this can be turned into arbitrary read/write on the JavaScript heap."

As is usual in these cases, Google acknowledged that an "exploit for CVE-2026-85046 exists in the wild," but did not reveal any details about the nature of the attacks, or who is behind them. This is done to ensure that a majority of the users are updated with a fix and to prevent other threat actors from exploiting it.

With the latest development, Google has addressed a total of six actively exploited Chrome zero-days since the start of the year. This includes CVE-2026-2441, CVE-2026-3909, CVE-2026-3910, CVE-2026-5281, and CVE-2026-11645.

For optimal protection, users are advised to update their Chrome browser to versions 152.0.7977.82/.83 for Windows and Apple macOS, and 152.0.7977.82 for Linux. To make sure the latest updates are installed, users can navigate to More > Help > About Google Chrome and select Relaunch.

Users of other Chromium-based browsers, such as Microsoft Edge, Brave, Opera, and Vivaldi, are also advised to apply the fixes as and when they become available.

Update

The U.S. Cybersecurity and Infrastructure Security Agency (CISA), on September 4, 2026, added CVE-2026-85046 to its Known Exploited Vulnerabilities (KEV) catalog, requiring Federal Civilian Executive Branch (FCEB) agencies to apply the patches by September 18, 2026.

Reproduced in full under licence from The Hacker News. © The Hacker News. Written by info@thehackernews.com (The Hacker News).

At a glance

Severity
Criticalfrom category and source signals; no CVSS referenced
Exploitation
Confirmed — 1 of 1 referenced vulnerability is on the CISA Known Exploited Vulnerabilities catalogue
Vulnerabilities
CVE-2026-85046
Vendors & products
Google, Chrome
Threat actors & malware
None named
Industries
Not industry-specific
Coverage
1 outlet· first seen 2026-09-04 07:18 UTC
Priority
64/100Source tier, category, exploitation and corroboration. Not a risk score for your environment.

Vulnerabilities referenced

  • CVE-2026-85046Exploited· due 2026-09-18

    Google Chromium V8

    Google Chromium V8 contains a type confusion vulnerability that allows a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. This vulnerability could affect multiple web browsers that utilize Chromium, including, but not limited to, Google Chrome, Microsoft Edge, and Opera.

    Added to KEV 2026-09-04

    Full record →

Coverage

One outlet has carried this so far.

  1. The Hacker NewsEstablished SourceFirst reported

    2026-09-04 07:18 UTC

Related stories