Malwarebytes Critical Chrome Zero-Day CVE-2026-85046 Exploited in the Wild
Article Content
- •CVE-2026-85046 is a high-severity zero-day vulnerability in Chrome's V8 engine.
- •Exploitation allows remote code execution via malicious HTML pages.
- •Google has confirmed active exploitation in the wild and recommends immediate updates.
Google has released an emergency update for Chrome to address CVE-2026-85046, a high-severity zero-day vulnerability in the V8 JavaScript and WebAssembly engine, rated 8.8 on the CVSS scale. The flaw, identified as a type confusion issue, allows remote attackers to execute arbitrary code within Chrome's sandbox by tricking users into visiting specially crafted HTML pages. This vulnerability is the sixth zero-day patched by Google in 2026, following previous exploits including CVE-2026-2441 and CVE-2026-5281. The update is being rolled out for Chrome versions 152.0.7977.82/.83 for Windows and macOS, and 152.0.7977.82 for Linux. Security researcher Salvatore Gulizia reported the flaw on August 4, 2026, and received a $1,000 bug bounty. Google has confirmed that the exploit is actively being used in the wild, prompting immediate action from users to update their browsers. Organizations are advised to apply the updates as soon as they are available to mitigate risks.
Ask AI about this cluster
Answers cite the sources they use
Timeline
More articles in this cluster (97)
Following this threat?
Track Sality, Google and CVE-2026-0768 in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.
Free account · no card needed
Continue Reading
AI Infrastructure Under Siege: Session Hijacking and Exploits Surge Recent cybersecurity incidents have targeted AI platforms and enterprise systems, with significant exploits reported. Notable vulnerabilities include the PaperCut remote code execution flaw (CVE-2026-65105) being actively exploited. Attackers are hijacking authenticated browser sessions for AI services like Claude…
HBO Max Account Compromise Fuels ClickFix Malware Campaign In September 2026, hackers compromised the verified HBO Max Reddit account, launching a ClickFix campaign that distributed 108 malicious ads over 48 hours. The ads targeted both macOS and Windows users, tricking them into executing commands that installed information-stealing malware. This operation, dubbed…