Chrome’s exploited-bug tally for 2026 hits six after V8 fix ships

Google patches the sixth Chrome zero-day of 2026 after attackers start exploiting a V8 type confusion bug.

CSBadmin
2 Min Read

Google has shipped a fresh stable build of Chrome to close CVE-2026-85046, a V8 type confusion flaw the company confirms is already being exploited in the wild. The fix takes Google’s count of attacked Chrome zero-days patched this year to six.

The bug, rated 8.8 on the CVSS scale, lets a remote attacker run arbitrary code inside the browser sandbox by luring a victim to a crafted HTML page. Researcher Salvatore Gulizia, who goes by Serotav, reported the flaw on August 4 and collected a $1,000 bounty. He described the root cause as a compiler mix-up that lets an array holding PACKED_ELEMENTS receive a PACKED_SMI_ELEMENTS map, a mismatch he said can be turned into arbitrary read and write access on the JavaScript heap.

Google credited the flaw to a type confusion in V8, the JavaScript and WebAssembly engine, and repeated its standard warning that an exploit exists in the wild while declining to share attack details until most users have updated.

The patched versions are 152.0.7977.82 and .83 on Windows and macOS and 152.0.7977.82 on Linux. Teams running Chromium-based browsers, including Microsoft Edge, Brave, Opera, and Vivaldi, should apply vendor fixes as they land, since the same engine flaw typically affects the whole family.

Earlier exploited zero-days Google closed in 2026 are CVE-2026-2441, CVE-2026-3909, CVE-2026-3910, CVE-2026-5281, and CVE-2026-11645.

To pull the update, users can open Chrome’s Help menu, select About Google Chrome, and relaunch once the download finishes. The release is rolling out gradually, so the new build may not appear in every region on day one.

CSBadmin

The latest in cybersecurity news and updates.

Share This Article
Follow:
The latest in cybersecurity news and updates.