Overview
- Google released Chrome 152.0.7977.82/.83 on Friday, September 4 to fix CVE-2026-85046 and 11 other security flaws, and the rollout is happening gradually to users on Windows, macOS, and Linux.
- CVE-2026-85046 is a high-severity type confusion bug in Chrome’s V8 JavaScript and WebAssembly engine that can corrupt memory to allow arbitrary read/write and possible remote code execution from a crafted web page.
- Google confirmed the bug has been used in the wild but withheld technical details until more users receive the patch to limit further abuse.
- The U.S. Cybersecurity and Infrastructure Security Agency added CVE-2026-85046 to its KEV catalog and set a federal remediation deadline of September 18, 2026, raising operational urgency for agencies and organizations.
- Other Chromium-based browsers are affected and administrators should prioritize applying vendor updates when available because this is the sixth actively exploited Chrome zero-day fixed in 2026, increasing the routine burden and attack risk for users and IT teams.