Google Fixes Sixth Actively Exploited Chrome Zero-Day in 2026
Google has released a Chrome security update to patch 12 vulnerabilities, including an actively exploited V8 zero-day flaw that could enable remote code execution through a crafted webpage. The bug affects Chrome's JavaScript and WebAssembly engine and was discovered by security researcher Salvatore Gulizia, known as Serotav, who reported it on August 4, 2026.
The CVE-2026-85046 vulnerability has a CVSS score of 8.8 and is the sixth actively exploited Chrome zero-day of 2026. Since the start of the year, Google has addressed six zero-day flaws exploited in attacks in the wild, including CVE-2026-2441, CVE-2026-3909, CVE-2026-3910, CVE-2026-5281, and CVE-2026-11645.
Google updated Chrome Stable to version 152.0.7977.82/.83 for Windows and Mac and 152.0.7977.82 for Linux, with the rollout happening over the coming days and weeks. Serotav received a $1,000 bug bounty for reporting the flaw.