Critical Chrome Zero-Day CVE-2026-85046 Exploited in the Wild

Critical Chrome Zero-Day CVE-2026-85046 Exploited in the Wild

First seen 4 Sep 2026, 08:45 UTC ExpressSecurityweekMalwarebytesMirrorCisecurity+28 80.8

Article Content

Browse articles
ThreatCluster

Google has released an emergency update for Chrome to address CVE-2026-85046, a high-severity zero-day vulnerability in the V8 JavaScript and WebAssembly engine, rated 8.8 on the CVSS scale. The flaw, identified as a type confusion issue, allows remote attackers to execute arbitrary code within Chrome's sandbox by tricking users into visiting specially crafted HTML pages. This vulnerability is the sixth zero-day patched by Google in 2026, following previous exploits including CVE-2026-2441 and CVE-2026-5281. The update is being rolled out for Chrome versions 152.0.7977.82/.83 for Windows and macOS, and 152.0.7977.82 for Linux. Security researcher Salvatore Gulizia reported the flaw on August 4, 2026, and received a $1,000 bug bounty. Google has confirmed that the exploit is actively being used in the wild, prompting immediate action from users to update their browsers. Organizations are advised to apply the updates as soon as they are available to mitigate risks.

Key Points: • CVE-2026-85046 is a high-severity zero-day vulnerability in Chrome's V8 engine. • Exploitation allows remote code execution via malicious HTML pages. • Google has confirmed active exploitation in the wild and recommends immediate updates.

Ask AI about this cluster

Timeline

2026-01-23
CVE-2026-0768 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE
2026-02-13
CVE-2026-2441 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE
2026-03-12
CVE-2026-3910 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE
2026-03-12
CVE-2026-3909 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE
2026-04-01
CVE-2026-5281 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE
2026-06-08
CVE-2026-11645 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE
2026-08-04
CVE-2026-85046 reported
Salvatore Gulizia reported the type confusion vulnerability in V8 to Google.
Socprime
2026-08-28
CVE-2026-81578 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE
2026-08-28
CVE-2026-82078 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE
2026-08-28
CVE-2026-82329 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE