Google warns of new Chrome zero-day flaw exploited in attacks - BleepingComputer

Google has released an emergency update for the Chrome browser to patch a high-severity zero-day vulnerability currently being exploited in the wild. Users are urged to update their browsers immediately to protect against potential remote code execution.
Why it matters
As Chrome is the world's most popular browser, unpatched vulnerabilities pose a significant security risk to millions of users and enterprise systems.
Google has updated the Chrome browser to address an actively exploited high-severity zero-day flaw in the V8 engine and 11 other vulnerabilities.
The exploited security issue, identified as CVE-2026-85046, is described as a type confusion. It was reported to Google by researcher Salvatore Gulizia, known online as "Serotav."
The update brings Chrome to version 152.0.7977.82/.83 on Windows and macOS, and 152.0.7977.82 on Linux, as part of a gradual rollout..
"Google is aware that an exploit for CVE-2026-85046 exists in the wild," the advisory reads .
The company did not disclose any technical or specific exploitation details about the flaw to give users and dependent projects time to apply the fix.
Type confusion flaws cause software to misinterpret one type of object as another, allowing attackers to corrupt memory.
V8 is Chrome's open-source JavaScript and WebAssembly engine, which compiles and executes code used by websites.
Get smarter about the news
Sign up free for a feed built around what you actually care about, Dive Deeper research on any story, and the full text of every article.
Create free accountAlready have an account? Sign in