Google Fixes Zero-Day Flaw Exploited by Attackers in Chrome Browser
Google has patched a high-severity zero-day flaw in its Chrome browser that was already being exploited by attackers. The issue, known as CVE-2026-85046, is a type confusion vulnerability in the V8 engine, which allows hackers to corrupt memory and potentially take control of a user's device. According to Google, an exploit for this flaw exists in the wild, but no technical details have been disclosed to give users time to apply the fix.
The company has released an update to Chrome, version 152.0.7977.82/.83 on Windows and macOS, and 152.0.7977.82 on Linux, as part of a gradual rollout. The patch addresses not only CVE-2026-85046 but also 11 other vulnerabilities.
The update was made available after researcher Salvatore Gulizia, known online as 'Serotav,' reported the issue to Google. While no further details have been shared about the exploitation technique, type confusion flaws are considered high-risk due to their potential for memory corruption and subsequent malicious activity.