Google Patches Sixth Chrome Zero-Day of 2026 As V8 Flaw Comes Under Active Attack
Google has released an urgent security update for Chrome to address a high-severity zero-day vulnerability in its V8 JavaScript engine. The flaw, currently being exploited in the wild, allows remote attackers to execute arbitrary code within the browser's sandbox.
Why it matters
As the world's most popular browser, a zero-day exploit in Chrome poses a significant security risk to billions of users and enterprise systems globally.
Google has released an urgent security update for Chrome after confirming that attackers are actively exploiting a high-severity vulnerability in the browser’s V8 JavaScript and WebAssembly engine.
The vulnerability, tracked as CVE-2026-85046 , is a type-confusion flaw that could allow a remote attacker to execute arbitrary code inside Chrome’s sandboxed renderer process after a user visits a maliciously crafted webpage.
Google addressed the zero-day as part of a broader Chrome 152 security update containing 12 fixes. The patched desktop versions are Chrome 152.0.7977.82 and 152.0.7977.83 for Windows and macOS, and 152.0.7977.82 for Linux.
The company is distributing the update gradually, but users and organizations should not wait for the browser’s normal automatic-update cycle. Chrome can be checked manually by opening the browser menu and selecting Help > About Google Chrome , or by visiting chrome://settings/help. The browser must be restarted after installation before the security fixes take effect.
Get smarter about the news
Sign up free for a feed built around what you actually care about, Dive Deeper research on any story, and the full text of every article.
Create free accountAlready have an account? Sign in