Chrome Zero-Day Under Active Exploitation: Update Your Browsers Now
Google has issued urgent security updates for its Chrome browser, addressing 12 vulnerabilities, including one actively exploited in the wild. This high-severity zero-day, tracked as **CVE-2026-85046**, is a type confusion bug in the **V8** JavaScript engine, allowing for arbitrary code execution within the browser's sandbox. Users are strongly advised to update immediately to mitigate the risk.

**Google** has released critical security updates for its **Chrome** browser, patching a total of 12 vulnerabilities. Among these, one particularly concerning flaw, designated **CVE-2026-85046**, is confirmed to be under active exploitation in the wild.
### The V8 Type Confusion Flaw
**CVE-2026-85046** carries a CVSS score of 8.8 and is classified as a type confusion bug within **V8**, Chrome's powerful JavaScript and WebAssembly engine. This vulnerability allows a remote attacker to execute arbitrary code within the browser's sandbox by enticing a user to visit a specially crafted HTML page.
Security researcher **Salvatore Gulizia** (also known as **Serotav**) is credited with discovering and reporting the flaw on August 4, 2026, receiving a $1,000 bug bounty for his responsible disclosure. Gulizia further elaborated on the issue in a separate blog post, describing it as a "**V8** bug in the compilers that leads to an array containing PACKED_ELEMENTS to receive the map PACKED_SMI_ELEMENTS, this can be turned into arbitrary read/write on the JavaScript heap."
### Active Exploitation and Google's Response
In line with standard practice, **Google** has acknowledged the existence of an exploit for **CVE-2026-85046** in the wild but has refrained from disclosing specific details regarding the attacks or the threat actors involved. This strategic silence is intended to allow a majority of users to update their browsers before further details could potentially aid other malicious actors.
This marks the sixth actively exploited Chrome zero-day addressed by **Google** since the beginning of the year. Previous zero-days include **CVE-2026-2441**, **CVE-2026-3909**, **CVE-2026-3910**, **CVE-2026-5281**, and **CVE-2026-11645**.
### Call to Action: Update Your Browsers
For optimal protection against this critical vulnerability and other patched flaws, users are strongly advised to update their **Chrome** browser immediately. The patched versions are 152.0.7977.82/.83 for Windows and Apple macOS, and 152.0.7977.82 for Linux.
To update, navigate to More > Help > About Google Chrome and select Relaunch. Users of other Chromium-based browsers, such as **Microsoft Edge**, **Brave**, **Opera**, and **Vivaldi**, should also apply available fixes as soon as their respective developers release them.