Overview
- Google released Chrome 152 this week to fix 12 vulnerabilities and said an exploit for CVE-2026-85046 is active in the wild.
- CVE-2026-85046 is a high-severity type confusion bug in V8, Chrome’s JavaScript and WebAssembly engine, that can let an attacker corrupt memory to read or write arbitrary data and execute code via a crafted HTML page.
- Security researcher Salvatore Gulizia reported the flaw on August 4 and received a $1,000 bug-bounty payment; Google declined to share technical exploitation details while the patch rolls out.
- The fix is available in Chrome 152.0.7977.82/.83 for Windows and macOS and 152.0.7977.82 for Linux, and users should check About Chrome and restart once the update arrives.
- This is the sixth Chrome zero-day Google has patched in 2026, highlighting ongoing attacker focus on browser engines and the need for fast updates by end users and other Chromium-based browser vendors.