Chrome users have another actively exploited zero-day to worry about, and this one sits inside the engine that powers much of the modern web.
Google has patched CVE-2026-85046, a high-severity type confusion vulnerability in Chrome’s V8 JavaScript and WebAssembly engine. The company confirmed that an exploit for the flaw exists in the wild, making it the sixth Chrome zero-day Google has patched so far in 2026.
Google has not disclosed who is exploiting the vulnerability, who has been targeted, or how the attacks work. That limited disclosure is intentional while the update rolls out, but it leaves users with one straightforward defense: get Chrome patched.
Chrome update fixes 12 security flaws
According to Google’s Chrome release notes, the latest update contains 12 security fixes and brings Chrome to versions 152.0.7977.82/.83 for Windows and macOS and 152.0.7977.82 for Linux.
CVE-2026-85046 was reported to Google by security researcher Salvatore Gulizia, also known as Serotav, on Aug. 4. Google awarded the researcher a $1,000 bounty.
The flaw is classified as a type confusion vulnerability in V8, the engine Chrome uses to process JavaScript and WebAssembly. Type confusion occurs when software treats a piece of data as the wrong type, potentially corrupting memory and creating conditions that attackers can exploit.
According to the CVE record, CVE-2026-85046 affects Chrome versions prior to 152.0.7977.82 and could allow a remote attacker to execute arbitrary code within Chrome’s sandbox via a crafted HTML page.
The company said access to vulnerability details may remain restricted until a majority of users have installed the fix.
Chrome zero-days are piling up in 2026
This is not Chrome’s first security update addressing an actively exploited vulnerability this year.
Google has now patched six Chrome zero-days in 2026, according to SecurityWeek: CVE-2026-2441, CVE-2026-3909, CVE-2026-3910, CVE-2026-5281, CVE-2026-11645, and now CVE-2026-85046.
In March, Google patched two actively exploited Chrome zero-days affecting the Skia graphics library and V8 engine.
Weeks later, the company fixed CVE-2026-5281, a critical use-after-free vulnerability affecting Chrome’s WebGPU implementation that was also being exploited in the wild.
Browsers are a constant target because they handle untrusted web content while providing access to everything from email and cloud services to financial accounts and enterprise applications.
Attackers are also looking beyond vulnerabilities in Chrome itself. eSecurity Planet previously reported on a malicious browser-extension campaign that injected remote JavaScript into authenticated browser sessions while evading traditional endpoint detection tools.
Together, these incidents show why browsers deserve the same security attention as other critical parts of the enterprise attack surface.
What Chrome users should do now
For individual Chrome users, the most important step is to verify that the latest update has actually installed.
Open Chrome, select the three-dot menu, and navigate to Help > About Google Chrome. Chrome should check for available updates automatically. Users may need to relaunch the browser to complete the installation.
Windows and macOS users should be running Chrome 152.0.7977.82/.83 or later, while Linux users should be on 152.0.7977.82 or later. Google said the update is rolling out over the coming days and weeks.
Some users may already see Chrome 153 because Google is rolling it out separately through its Early Stable channel to a small percentage of users.
Google also released Chrome 152.0.7977.82 for Android and said Android releases include the same security fixes as their corresponding desktop releases unless otherwise noted.
For IT administrators, relying on Chrome’s automatic updater may not be enough. Organizations should verify browser versions across managed endpoints and identify systems that have not yet received the update.
Because Google is rolling out the patch gradually, some devices may still be waiting for the new version. Admins should keep monitoring those systems, especially endpoints that access sensitive business applications.
Google has not disclosed how widespread the attacks are or who is being targeted. With exploitation already confirmed, organizations should make sure the patched version is installed as soon as it becomes available.
Related reading: For more on the growing risks inside the browser, read how browser threats are expanding the enterprise attack surface.





