Malwarebytes
Active Exploitation of Chrome V8 Zero-Day Vulnerability CVE-2026-85046
Article Content
Google has released a critical update for Chrome to address 12 vulnerabilities, including CVE-2026-85046, a type confusion flaw in the V8 JavaScript engine that is actively being exploited. This vulnerability allows remote attackers to execute arbitrary code within the browser's sandbox via specially crafted HTML pages. The flaw was reported by security researcher Salvatore Gulizia on August 4, 2026, and has a CVSS score of 8.8. Google confirmed that an exploit for this vulnerability exists in the wild, marking it as the sixth actively exploited zero-day of 2026. Users are urged to update to Chrome version 152.0.7977.82/.83 for Windows and Mac, and 152.0.7977.82 for Linux. The update rollout is ongoing, and users of other Chromium-based browsers should also apply the fixes as they become available.
Key Points: • CVE-2026-85046 is a critical type confusion vulnerability in Chrome's V8 engine. • The flaw allows remote code execution via crafted HTML pages and is actively exploited. • Google has released updates to patch this vulnerability across all supported platforms.
Ask AI about this cluster
Answers cite the sources they use
Analyzing cluster data...
Referenced clusters
Something went wrong. Please try again.