Google Patches Actively Exploited Chrome V8 Zero-Day CVE-2026-85046, Sixth In-the-Wild Fix of 2026
Google Patches Actively Exploited Chrome V8 Zero-Day CVE-2026-85046, Sixth In-the-Wild Fix of 2026
Google has issued an emergency stable-channel update for Chrome to address a high-severity vulnerability that was already being exploited in the wild before a fix became available, according to the company's own advisory. The flaw, tracked as CVE-2026-85046, affects the V8 JavaScript engine that powers Chrome's core functionality. Many observers note that this marks the sixth actively exploited Chrome zero-day patched in 2026, continuing a pattern of frequent browser-engine attacks that security researchers have tracked throughout the year.
Inside the Vulnerability: A Type Confusion Bug in V8
CVE-2026-85046 is a type confusion vulnerability within V8, Chrome's JavaScript and WebAssembly engine. The bug carries a CVSS severity score of 8.8, reflecting its potential impact. Reports indicate that a specially crafted HTML page could trigger heap corruption inside Chrome's sandboxed renderer process. If successfully exploited, this type of flaw could allow an attacker to execute arbitrary code, though the browser's sandbox architecture is designed to contain such attempts and limit broader system compromise.
Who Found It, and How Google Responded
The vulnerability was reported to Google by researcher Salvatore Gulizia, who publishes under the handle Serotav, on August 4, 2026. Gulizia received a $1,000 bug bounty for the disclosure. Consistent with standard practice for actively exploited vulnerabilities, Google withheld detailed technical specifics about the exploitation in its advisory, a common industry approach intended to limit further abuse while broader patch adoption is still underway. A recurring consumer concern in coverage of this incident is the limited visibility into who is behind the exploitation and how the vulnerability has been used, though this is typical of early-stage disclosures.
Patch Details and Rollout Timeline
The fix has landed in Chrome 152.0.7977.82 and 152.0.7977.83 for Windows and macOS, and in Chrome 152.0.7977.82 for Linux. As is standard for Chrome's stable channel, the update is rolling out gradually to users over the coming days and weeks rather than all at once, meaning some users may not receive the patch immediately.
Federal Deadline: CISA's KEV Catalog Listing
The Cybersecurity and Infrastructure Security Agency added CVE-2026-85046 to its Known Exploited Vulnerabilities catalog on September 4, 2026. This listing requires Federal Civilian Executive Branch agencies to remediate the flaw by September 18, 2026. The CISA designation is generally viewed as a strong signal that a vulnerability has documented real-world exploitation, reinforcing the urgency communicated in Google's own advisory.
A Pattern of Chrome Zero-Days in 2026
Most tracking sources describe CVE-2026-85046 as the sixth actively exploited Chrome zero-day patched by Google in 2026. Notably, at least one outlet has characterized it as the seventh such flaw, a discrepancy that appears to stem from differing methodologies in how each outlet counts or verifies prior incidents. This inconsistency is worth flagging rather than treating either figure as definitive. Regardless of the exact count, the recurring cadence of these disclosures has led many observers to note sustained attacker interest in browser engine vulnerabilities as a persistent trend throughout the year.
What Users and IT Teams Should Do Now
Chrome users are encouraged to confirm their browser has updated to a patched version by checking the application's version and update settings. Because the rollout is gradual, some users may need to manually trigger a check for updates. Users of other Chromium-based browsers, including Microsoft Edge, Brave, and Opera, may remain exposed until those vendors incorporate the underlying V8 fix into their own releases. Organizations, and federal agencies in particular given the CISA deadline, are advised to prioritize patch deployment across their environments as soon as possible.