// uncategorised

Google Patches Chrome’s Sixth Zero-Day of 2026

Google has patched the sixth actively exploited Chrome zero-day of 2026, and the bug lives in the same place most of the serious ones do: the V8 JavaScript and WebAssembly engine.

CVE-2026-85046 is a type confusion flaw in V8, shipped as part of Chrome 152, which resolved 12 vulnerabilities in total. Google confirms an exploit for this one already exists in the wild. Type confusion bugs in V8 are memory corruption issues that a crafted HTML page can trigger to perform out-of-bounds reads and writes, which is the standard path from “renderer bug” to remote code execution in a browser. The fix landed in Chrome 152.0.7977.82/.83 for Windows and macOS and 152.0.7977.82 for Linux, alongside nine other high-severity fixes covering use-after-free, race condition, and out-of-bounds issues. The researcher who reported it, Salvatore Gulizia, picked up a $1,000 bounty.

Six zero-days patched in a single year is not an anomaly for Chrome at this point, it is close to the baseline. What makes each one worth individual attention is that a V8 bug reachable from a web page is one of the few vulnerability classes that needs nothing from the victim beyond loading a page, which is why these keep showing up as the delivery mechanism in targeted campaigns rather than commodity malware.

Update Chrome now if auto-update has not already done it, and check any Chromium-based browser in your environment separately, since they typically lag the official patch by days. Browser-delivered compromise is exactly the kind of initial-access path our web application penetration testing engagements account for when mapping how an attacker actually gets a foothold.


// get started

Work with AgentOffense

Tell us about your target and goals. We’ll reply with scope and a fixed-price quote — usually within one business day.

./request_engagement