
Google has updated the Chrome browser to address an actively exploited high-severity zero-day flaw in the V8 engine and 11 other vulnerabilities.
The security issue in use, identified as CVE-2026-85046, is described as type confusion. This was reported to Google by researcher Salvatore Guliza, known online as “Serotav”.
The update brings Chrome to version 152.0.7977.82/.83 for Windows and macOS and 152.0.7977.82 for Linux as part of a gradual rollout.
“Google is aware that an exploit for CVE-2026-85046 exists in the wild,” the advice reads.
The company did not disclose any technical or specific operational details about the flaw to give users and dependent projects time to apply the fix.
Type confusion flaws cause software to misinterpret one type of object as another, allowing attackers to corrupt memory.
V8 is Chrome’s open source JavaScript and WebAssembly engine that compiles and executes code used by websites.
Therefore, CVE-2026-85046 could potentially be triggered by a specially crafted HTML page containing malicious JavaScript, potentially allowing remote code execution within Chrome’s sandboxed rendering process.
The update also addresses nine other high-severity vulnerabilities, including post-use and out-of-bounds memory leaks in Crash Reporting, Networking, Compositing, WebGL, CacheStorage, DevTools, Skia, and race condition in V8.
CVE-2026-85046 is the sixth actively exploited bug that Google has fixed in Chrome since the beginning of the year. Previous fixes include:
- Out-of-bounds read/write vulnerability in Chrome’s V8 JavaScript engine (CVE-2026-11645), exploited in the wild and patched in June.
- Iterator invalidation vulnerability (CVE-2026-2441) in CSSFontFeatureValuesMap, Chrome’s implementation of CSS font feature values, fixed in mid-February.
- Two additional Chrome zero days exploited in March attacks: an out-of-bounds write bug in the Skia 2D graphics library (CVE-2026-3909) and an inappropriate implementation issue in the V8 JavaScript and WebAssembly engine (CVE-2026-3910).
- A post-free use vulnerability in Dawn (CVE-2026-5281), the cross-platform implementation of the WebGPU standard used by Chromium, was fixed in April.
Chrome users are advised to apply the available update as soon as the rollout reaches them by opening Settings > About Chrome and waiting for the update to download and install.

After the update process is complete, a browser restart is required to apply the fixes.
Similar action is recommended for users of Chrome-based browsers, including Microsoft Edge, Brave, Opera, and Vivaldi, although it may take a few extra days for fixes to arrive in these apps.
Generic prevention scores can hide what happens after initial access. Once attackers use valid credentials, prevention plummets.
The 2026 Blue Report measures security techniques by techniques in 338 million simulations run in customer production environments.
