Google has patched CVE-2026-85046, a high-severity (CVSS 8.8) type confusion vulnerability residing in the V8 JavaScript and WebAssembly engine. This zero-day flaw is being actively exploited in the wild, enabling remote code execution (RCE) when a user interacts with malicious web content. The vulnerability has been formally added to the CISA Known Exploited Vulnerabilities (KEV) Catalog, mandating rapid remediation. This incident represents the sixth Chrome-specific zero-day exploitation recorded in 2026. Immediate updates to Chrome version 152.0.7977.82 or 152.0.7977.83 across Windows, macOS, and Linux are required to prevent unauthorized system access and arbitrary code execution.
-
Vulnerability Architecture: Type Confusion
- Located within the V8 engine, which is responsible for executing JavaScript and WebAssembly.
- Occurs when the engine incorrectly interprets an object as a different type, leading to memory corruption.
- Allows an attacker to bypass memory safety mechanisms to achieve arbitrary memory read/write primitives.
-
Exploitation Dynamics: Active Zero-Day
- Attack vector is purely remote, requiring the victim to visit a specially crafted malicious website.
- Exploitation is currently active in the wild, targeting users across multiple operating systems.
- Successfully exploited flaws facilitate full Remote Code Execution (RCE) on the host machine.
-
Regulatory & Trend Analysis: Criticality
- Included in the CISA KEV Catalog, signaling an immediate risk to enterprise and government infrastructure.
- Highlights an escalating threat landscape, marking the sixth Chrome zero-day exploited in 2026.
- Broad platform scope ensures high impact across Windows, macOS, and Linux environments.
-
Remediation: Patch Deployment
- Windows and macOS users must update to Chrome version 152.0.7977.82 or 152.0.7977.83.
- Linux users must update to version 152.0.7977.82.
- Enterprise administrators should prioritize forced updates via Group Policy (GPO) or MDM solutions to ensure fleet-wide compliance.
Related posts
- threatprotect.qualys.com — Google Chrome Zero-day Vulnerability Exploited in the Wild (CVE-2026-85046)
- thehackernews.com — Google Releases Chrome Update to Patch Actively Exploited V8 Zero-Day
- helpnetsecurity.com — Google patches actively exploited Chrome zero-day (CVE-2026-85046)
- socprime.com — CVE-2026-85046: Actively Exploited Chrome V8 Zero-Day Enables Code Execution
- eSecurity Planet — Google’s Chrome Update Patches Sixth Zero-Day Exploited in 2026
- Bleepingcomputer
- Shattered
- Cybernews
- Forbes