Particle.news

Google Patches Actively Exploited V8 Zero-Day in Chrome Update

CISA’s addition of the flaw to its Known Exploited Vulnerabilities catalog requires federal agencies to remediate by September 18, 2026.

Overview

  • Google on Thursday released Chrome 152.0.7977.82/.83 to fix 12 vulnerabilities and confirmed an exploit for CVE-2026-85046 is being used in the wild.
  • CVE-2026-85046 is a high‑severity type confusion bug in Chrome’s V8 JavaScript and WebAssembly engine that can let crafted web pages corrupt memory and enable code execution inside the browser sandbox.
  • Researcher Salvatore Gulizia reported the flaw on August 4, 2026, published a technical write-up describing a compiler-caused map swap (PACKED_ELEMENTS receiving PACKED_SMI_ELEMENTS) that enables arbitrary read/write, and received a $1,000 bounty.
  • The U.S. Cybersecurity and Infrastructure Security Agency added the vulnerability to its Known Exploited Vulnerabilities catalog and ordered federal fixes by September 18, 2026, while Chromium-based browser vendors are urged to push equivalent patches.
  • This is the sixth actively exploited Chrome zero-day patched in 2026, a pattern that raises pressure on organizations and users to install the update and restart their browsers immediately to reduce risk.