bleepingcomputer.com web signal

Google patches sixth Chrome zero-day of 2026 exploited in wild

Google Cybersecurity ai-business

TL;DR

  • Google shipped Chrome 152.0.7977.82/.83 to fix CVE-2026-85046, a type-confusion bug in the V8 JavaScript engine already exploited in the wild.
  • The flaw is the sixth Chrome zero-day Google has patched in 2026; researcher Salvatore Gulizia reported it and received a $1,000 bounty.
  • The same update fixes nine other high-severity bugs across Crash Reporting, Network, Compositing, WebGL, CacheStorage, DevTools and Skia.

Google shipped Chrome 152.0.7977.82/.83 to patch CVE-2026-85046, a type-confusion vulnerability in the V8 JavaScript and WebAssembly engine that is being exploited in the wild. BleepingComputer reported it is the sixth Chrome zero-day Google has fixed in 2026.

The advisory quotes Google saying: "Google is aware that an exploit for CVE-2026-85046 exists in the wild." Type-confusion bugs cause software to misinterpret one object type as another, potentially corrupting memory; in V8, that path can lead to remote code execution inside Chrome's sandboxed renderer when a user opens a page carrying crafted JavaScript.

The flaw was reported by researcher Salvatore Gulizia, who was awarded a $1,000 bug bounty. The same release patches nine other high-severity issues across Crash Reporting, Network, Compositing, WebGL, CacheStorage, DevTools and Skia, plus a race condition in V8. Google did not name who is running the exploit or how many users have been hit. It joins 252 cybersecurity items in our last 90 days of tracking.