Overview
- Google on Thursday released Chrome 152.0.7977.82/.83 to fix 12 vulnerabilities and confirmed an exploit for CVE-2026-85046 is being used in the wild.
- CVE-2026-85046 is a high‑severity type confusion bug in Chrome’s V8 JavaScript and WebAssembly engine that can let crafted web pages corrupt memory and enable code execution inside the browser sandbox.
- Researcher Salvatore Gulizia reported the flaw on August 4, 2026, published a technical write-up describing a compiler-caused map swap (PACKED_ELEMENTS receiving PACKED_SMI_ELEMENTS) that enables arbitrary read/write, and received a $1,000 bounty.
- The U.S. Cybersecurity and Infrastructure Security Agency added the vulnerability to its Known Exploited Vulnerabilities catalog and ordered federal fixes by September 18, 2026, while Chromium-based browser vendors are urged to push equivalent patches.
- This is the sixth actively exploited Chrome zero-day patched in 2026, a pattern that raises pressure on organizations and users to install the update and restart their browsers immediately to reduce risk.