Chrome Zero-Day Exploit Exposed: Update Browser Now
Google has released an urgent security update for Chrome to patch 12 vulnerabilities, including a high-severity zero-day that is already being exploited in the wild. The vulnerability, tracked as CVE-2026-85046 with a severity rating of 8.8, was reported by researcher Salvatore Gulizia on August 4th and earned him a $1,000 bug bounty for the disclosure.
The flaw affects V8, Google's open-source JavaScript and WebAssembly engine, and is a type confusion vulnerability that can allow attackers to execute malicious code, crash the system, or steal sensitive data. The company has confirmed that an exploit for CVE-2026-85046 exists in the wild, but has not specified who is exploiting it, who is being targeted, or how widely it has been used.
Users are advised to update Chrome and relaunch the browser to install version 152.0.7977.82 or later. This is the sixth Chrome zero-day Google has patched in 2026, following previous vulnerabilities including CVE-2026-2441, CVE-2026-3909, CVE-2026-3910, CVE-2026-5281, and CVE-2026-11645.