started · updated
Google Chrome patches actively exploited V8 zero-day vulnerability
Google has released an urgent security update for Chrome to address CVE-2026-85046, a high-severity zero-day vulnerability in the V8 JavaScript and WebAssembly engine. The flaw, classified as a type confusion issue, has been confirmed to be actively exploited in the wild. It allows remote attackers to execute arbitrary code within the browser's sandbox by tricking the engine into mishandling memory, often via a specially crafted HTML page.
This marks the sixth actively exploited Chrome zero-day of 2026. The vulnerability carries a CVSS score of 8.8. Because the flaw resides in the V8 engine, it also affects other Chromium-based browsers, including Microsoft Edge, Brave, Opera, and Vivaldi. Microsoft has already released corresponding updates for Edge to mitigate the risk.
Security researcher Salvatore Gulizia, also known as Serotav, reported the vulnerability and received a $1,000 bug bounty from Google. Users are strongly advised to update to Chrome version 152.0.7977.82/.83 on Windows and macOS, or 152.0.7977.82 on Linux, and restart their browsers immediately to ensure protection.
Entities
CISA · Chromium · ENISA · Google · Microsoft · Salvatore Gulizia · V8
Claims
What the coverage asserts, and how many sources carry each claim.
- [● 11 SOURCES] The V8 vulnerability allows remote attackers to execute arbitrary code inside the browser sandbox via a crafted HTML page. revistametronomo.com · www.chiccheinformatiche.com · cybernoz.com · www.iphoneincanada.ca · www.it-boltwise.de · +6 more
- [● 9 SOURCES] Google released a security update for Chrome to fix 12 vulnerabilities. revistametronomo.com · borncity.com · thenextweb.com · www.chiccheinformatiche.com · cybernoz.com · +3 more
- [● 7 SOURCES] CVE-2026-85046 is the sixth actively exploited Chrome zero-day of 2026. borncity.com · thenextweb.com · www.chiccheinformatiche.com · cybernoz.com · www.iphoneincanada.ca · +2 more
- [● 5 SOURCES] Microsoft released an update for Edge to address the CVE-2026-85046 vulnerability. www.deskmodder.de · www.drweb.de · www.leak.pt · mobiili.fi · techplanet.today
- [● 9 SOURCES] CVE-2026-85046 has been assigned a CVSS score of 8.8. revistametronomo.com · borncity.com · www.chiccheinformatiche.com · cybernoz.com · www.leak.pt · +3 more
- [● 6 SOURCES] The vulnerability affects all Chromium-based browsers, including Brave, Opera, and Vivaldi. www.drweb.de · www.iphoneincanada.ca · www.leak.pt · mobiili.fi · techplanet.today · +1 more
- [● 3 SOURCES] CISA added the Chromium V8 flaw to its Known Exploited Vulnerabilities catalog on September 4, 2026. www.drweb.de · securityaffairs.com
- [● 4 SOURCES] Salvatore Gulizia reported the V8 flaw and received a $1,000 bug bounty. borncity.com · thenextweb.com · cybernoz.com · www.iphoneincanada.ca