< Back to all clusters
[TECHNOLOGY] · United States · 15 sources

started · updated

Google Chrome patches actively exploited V8 zero-day vulnerability

Google has released an urgent security update for Chrome to address CVE-2026-85046, a high-severity zero-day vulnerability in the V8 JavaScript and WebAssembly engine. The flaw, classified as a type confusion issue, has been confirmed to be actively exploited in the wild. It allows remote attackers to execute arbitrary code within the browser's sandbox by tricking the engine into mishandling memory, often via a specially crafted HTML page.

This marks the sixth actively exploited Chrome zero-day of 2026. The vulnerability carries a CVSS score of 8.8. Because the flaw resides in the V8 engine, it also affects other Chromium-based browsers, including Microsoft Edge, Brave, Opera, and Vivaldi. Microsoft has already released corresponding updates for Edge to mitigate the risk.

Security researcher Salvatore Gulizia, also known as Serotav, reported the vulnerability and received a $1,000 bug bounty from Google. Users are strongly advised to update to Chrome version 152.0.7977.82/.83 on Windows and macOS, or 152.0.7977.82 on Linux, and restart their browsers immediately to ensure protection.

Entities

CISA · Chromium · ENISA · Google · Microsoft · Salvatore Gulizia · V8

Claims

What the coverage asserts, and how many sources carry each claim.

Sources

10 days ago