Google Patches 6th Chrome Zero-Day of 2026

On Thursday, Google released new Chrome 152 security updates that resolve 12 vulnerabilities, including a zero-day exploit.

Tracked as CVE-2026-85046the high-severity error is described as a type confusion issue in Chrome’s V8 JavaScript and WebAssembly engines. This was reported by Salvatore Guliza, who received a $1000 bug bounty.

“Google is aware that the exploit for CVE-2026-85046 exists in the wild,” the Internet giant said consultative reads.

Although the company did not share details about the security flaw, the type confusion flaws in the V8 engine could be used to perform remote read/write operations through crafted HTML pages.

Confusion vulnerabilities are memory-corrupting errors that can lead to crashes, remote code execution, and other malicious behavior.

CVE-2026-85046 is the sixth Chrome zero-day fixed in 2026. The other five are CVE-2026-2441, CVE-2026-3909, CVE-2026-3910, CVE-2026-5281, and CVE-2026-11645.

Advertising. Scroll to continue reading.

The security flaw was resolved in Chrome versions 152.0.7977.82/.83 for Windows and macOS and version 152.0.7977.82 for Linux.

The updates address nine other high-severity bugs, including out-of-bounds read/write, incomplete cleanup, use-after-free, race condition, improper resource exposure, and type confusion issues. Three of these were reported by external researchers.

In addition, Google fixed two medium-severity vulnerabilities of incorrect input validation and usage after free.

Related: Chrome and Firefox updates fix dozens of vulnerabilities

Related: Chrome 152 fixes over 300 vulnerabilities

Related: Over 3 million WordPress sites affected by migration plugin vulnerability

Related: Cisco warns of unpatched flaws in secure email, fixes critical switch vulnerabilities

Leave a Reply

Your email address will not be published. Required fields are marked *