Chrome Patches Sixth Zero-Day Exploit of 2026
Google has issued an update for its Chrome browser to patch a total of 12 vulnerabilities, including a high-severity zero-day exploit that was actively being used in the wild. The bug, tracked as CVE-2026-85046, is a type confusion issue in Chrome's V8 JavaScript and WebAssembly engine.
The security defect may be exploited to perform remote read/write operations via crafted HTML pages. Type confusion vulnerabilities can lead to memory corruption bugs that cause crashes, remote code execution, and other malicious behavior.
Google is aware of the exploit existing in the wild, but has not shared further details on the security defect. The company's advisory notes that it has awarded a $1,000 bug bounty reward to Salvatore Gulizia for reporting the issue.