Google has updated Chrome to fix an actively exploited, high-severity zero-day vulnerability in its V8 engine, along with 11 other vulnerabilities.
Tracked as CVE-2026-85046, the exploited flaw is classified as a type confusion issue. Google credited researcher Salvatore Gulizia, known online as “Serotav,” with reporting it.
The company said it is aware that an exploit for CVE-2026-85046 exists in the wild. Google did not disclose technical or specific exploitation details, giving users and dependent projects time to apply the fix.
The update moves Chrome to version 152.0.7977.82/.83 on Windows and macOS, and to 152.0.7977.82 on Linux, as part of a gradual rollout.
Type confusion flaws can cause software to interpret one object type as another, potentially enabling memory corruption. Because V8 compiles and executes JavaScript and WebAssembly used by websites, the vulnerability could potentially be triggered by a specially crafted HTML page containing malicious JavaScript and allow remote code execution within Chrome’s sandboxed renderer process.
The update also addresses nine other high-severity vulnerabilities, including use-after-free and out-of-bounds memory flaws affecting Crash Reporting, Network, Compositing, WebGL, CacheStorage, DevTools, Skia, and V8.
CVE-2026-85046 is the sixth actively exploited Chrome bug Google has fixed since the start of the year.
Comments
0No comments yet. Be the first to comment.