On Thursday, Google released new Chrome 152 security updates that resolve 12 vulnerabilities, including a zero-day exploit.
Tracked as CVE-2026-85046the high-severity error is described as a type confusion issue in Chrome’s V8 JavaScript and WebAssembly engines. This was reported by Salvatore Guliza, who received a $1000 bug bounty.
“Google is aware that the exploit for CVE-2026-85046 exists in the wild,” the Internet giant said consultative reads.
Although the company did not share details about the security flaw, the type confusion flaws in the V8 engine could be used to perform remote read/write operations through crafted HTML pages.
Confusion vulnerabilities are memory-corrupting errors that can lead to crashes, remote code execution, and other malicious behavior.
CVE-2026-85046 is the sixth Chrome zero-day fixed in 2026. The other five are CVE-2026-2441, CVE-2026-3909, CVE-2026-3910, CVE-2026-5281, and CVE-2026-11645.
The security flaw was resolved in Chrome versions 152.0.7977.82/.83 for Windows and macOS and version 152.0.7977.82 for Linux.
The updates address nine other high-severity bugs, including out-of-bounds read/write, incomplete cleanup, use-after-free, race condition, improper resource exposure, and type confusion issues. Three of these were reported by external researchers.
In addition, Google fixed two medium-severity vulnerabilities of incorrect input validation and usage after free.
Related: Chrome and Firefox updates fix dozens of vulnerabilities
Related: Chrome 152 fixes over 300 vulnerabilities
Related: Over 3 million WordPress sites affected by migration plugin vulnerability
Related: Cisco warns of unpatched flaws in secure email, fixes critical switch vulnerabilities