Google patches sixth Chrome zero-day of 2026 exploited in wild
TL;DR
- Google shipped Chrome 152.0.7977.82/.83 to fix CVE-2026-85046, a type-confusion bug in the V8 JavaScript engine already exploited in the wild.
- The flaw is the sixth Chrome zero-day Google has patched in 2026; researcher Salvatore Gulizia reported it and received a $1,000 bounty.
- The same update fixes nine other high-severity bugs across Crash Reporting, Network, Compositing, WebGL, CacheStorage, DevTools and Skia.
Google shipped Chrome 152.0.7977.82/.83 to patch CVE-2026-85046, a type-confusion vulnerability in the V8 JavaScript and WebAssembly engine that is being exploited in the wild. BleepingComputer reported it is the sixth Chrome zero-day Google has fixed in 2026.
The advisory quotes Google saying: "Google is aware that an exploit for CVE-2026-85046 exists in the wild." Type-confusion bugs cause software to misinterpret one object type as another, potentially corrupting memory; in V8, that path can lead to remote code execution inside Chrome's sandboxed renderer when a user opens a page carrying crafted JavaScript.
The flaw was reported by researcher Salvatore Gulizia, who was awarded a $1,000 bug bounty. The same release patches nine other high-severity issues across Crash Reporting, Network, Compositing, WebGL, CacheStorage, DevTools and Skia, plus a race condition in V8. Google did not name who is running the exploit or how many users have been hit. It joins 252 cybersecurity items in our last 90 days of tracking.
Originally reported by bleepingcomputer.com
Read the original article →Original headline: Google Patches Chrome V8 Zero-Day CVE-2026-85046 Under Active Exploitation, Sixth of 2026