Particle.news

Google Issues Emergency Chrome Patch for Actively Exploited V8 Zero‑Day

CISA has added the flaw to its Known Exploited Vulnerabilities catalog, ordering federal agencies to remediate by September 18, 2026.

Overview

  • Google released Chrome 152.0.7977.82/.83 on Friday, September 4 to fix CVE-2026-85046 and 11 other security flaws, and the rollout is happening gradually to users on Windows, macOS, and Linux.
  • CVE-2026-85046 is a high-severity type confusion bug in Chrome’s V8 JavaScript and WebAssembly engine that can corrupt memory to allow arbitrary read/write and possible remote code execution from a crafted web page.
  • Google confirmed the bug has been used in the wild but withheld technical details until more users receive the patch to limit further abuse.
  • The U.S. Cybersecurity and Infrastructure Security Agency added CVE-2026-85046 to its KEV catalog and set a federal remediation deadline of September 18, 2026, raising operational urgency for agencies and organizations.
  • Other Chromium-based browsers are affected and administrators should prioritize applying vendor updates when available because this is the sixth actively exploited Chrome zero-day fixed in 2026, increasing the routine burden and attack risk for users and IT teams.