Google Patches 12 Chrome Flaws, Including Actively Exploited Zero-Day
Google released a critical security update for Chrome on September 3, 2026, patching 12 vulnerabilities. The most severe flaw, CVE-2026-85046, was already under active exploitation and has a CVSS score of 8.8.
The bug is a type confusion in the V8 JavaScript engine, which allows remote attackers to execute arbitrary code inside the sandbox via a crafted HTML page.
This marks the sixth actively exploited Chrome zero-day Google has patched since the start of 2026, with all six having a CVSS score of 8.8.
Researcher Salvatore Gulizia reported the bug on August 4, 2026, and received a $1,000 bug bounty from Google. The company confirmed an in-the-wild exploit exists but withheld attack details to slow further abuse.