Google urgently fixes new Chrome vulnerability already exploited by hackers

06.09.2026 2 minutes Author: Newsman

Google has released a new security update that fixes 12 vulnerabilities in Chrome, including a dangerous zero-day flaw that attackers are already actively exploiting.

The vulnerability, tracked as CVE-2026-85046 and rated 8.8 on the CVSS scale, was reported by researcher Salvatore Gulizia on August 4. He received a $1,000 reward for disclosing it.

CVE-2026-85046 is a type confusion vulnerability in V8, Google’s open-source JavaScript and WebAssembly engine. Such flaws can cause software to misidentify data types, potentially allowing attackers to execute malicious code, crash the system, or steal sensitive information.

The company confirmed that it is aware of an exploit for CVE-2026-85046. However, Google did not specify who is using the vulnerability, who is being targeted, or how widely it has been exploited.

“Type confusion in V8 in versions of Google Chrome prior to 152.0.7977.82 allowed a remote attacker to execute arbitrary code inside the sandbox via a specially crafted HTML page,” according to the CVE record for CVE-2026-85046.

In a post on his blog, Gulizia described the issue as “a bug in the V8 compilers that causes an array containing PACKED_ELEMENTS to receive the PACKED_SMI_ELEMENTS map.” Put simply, V8 incorrectly identifies the type of data stored in an array. This allows an attacker to manipulate certain areas of the browser’s memory.

The update is already available as Chrome 152.0.7977.82 and 152.0.7977.83 for Windows and macOS, as well as Chrome 152.0.7977.82 for Linux. The remaining users are expected to receive it in the coming days or weeks. Chrome 152.0.7977.82 is also gradually rolling out to Android users.

This is the sixth Chrome zero-day vulnerability patched by Google in 2026. The company previously fixed CVE-2026-2441, CVE-2026-3909, CVE-2026-3910, CVE-2026-5281, and CVE-2026-11645.

Chrome users are advised to check whether they have the latest version of the browser installed. To do so, open the menu, go to “Help,” select “About Google Chrome,” wait for the update to finish installing, and click “Relaunch.”

Google has also recently faced other security issues. Researchers from New York University and Radboud University developed a modular detection system called AdLens. It analyzed 188,000 ad creatives using open-weight artificial intelligence models, including Google’s Gemma, and identified hundreds of deceptive software advertisements.

Subscribe
Notify of
0 Коментарі
Oldest
Newest Most Voted
Found an error?
If you find an error, take a screenshot and send it to the bot.