Google Patches Actively Exploited Chrome Zero-Day – Update Now

Google Patches Actively Exploited Chrome Zero-Day – Update Now

Google just dropped an emergency Chrome update, and this one’s not optional. They’ve patched CVE-2026-85046 — a high-severity type confusion bug in the V8 JavaScript engine that’s already being actively exploited in the wild.

Here’s what you need to know.

The Vulnerability

The flaw sits in V8, the engine that compiles and runs JavaScript and WebAssembly code for every page you visit. It’s a type confusion issue (CWE-843), which basically means Chrome misinterprets one type of data as another. Security researcher Salvatore Gulizia (who goes by “Serotav”) discovered it and reported it to Google on August 4.

In practical terms: visiting a malicious or compromised website could let an attacker execute arbitrary code inside Chrome’s sandbox. The sandbox limits the damage, but attackers often combine this type of flaw with another bug to escape the sandbox and take full control of your machine.

The Fix

Google released the patch on September 3 as part of Chrome Stable version 152.0.7977.82/.83.

Platform:    Fixed Version
Windows:    152.0.7977.82 / .83
macOS:        152.0.7977.82 / .83
Linux:           152.0.7977.82

To update: Click the three-dot menu → Help → About Google Chrome. Chrome will check for updates and prompt you to relaunch.

The Bigger Picture

This is the sixth actively exploited Chrome zero-day Google has patched in 2026. The previous five include:
  • CVE-2026-2441 – CSS font feature values (February)
  • CVE-2026-3909 & CVE-2026-3910 – Skia graphics and V8 (March)
  • CVE-2026-5281 – Dawn use-after-free (April)
  • CVE-2026-11645 – V8 out-of-bounds (June)
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has already added CVE-2026-85046 to its Known Exploited Vulnerabilities catalog, giving federal agencies until September 18 to patch.

And if you use other Chromium-based browsers—Edge, Brave, Opera, Vivaldi—you’re not off the hook. They’ll need to roll out their own fixes too.

Bottom Line

This isn’t a theoretical risk. Attackers are using it right now. Don’t put this update off.

إرسال تعليق

أحدث أقدم