Google Patches Critical Chrome Flaw Ahead of EU's New Security Laws
Google recently patched 12 vulnerabilities in Chrome, including CVE-2026-85046, a type confusion bug in V8 being exploited by attackers. This is the sixth such flaw this year.
The bug has a CVSS score of 8.8 and allows a remote attacker to run code inside the sandbox through a crafted web page. The fixed builds are 152.0.7977.82 and .83, with Google withholding details until most browsers were patched.
Salvatore Gulizia reported the bug on August 4 and received $1,000 from Chrome's programme, which pays up to $250,000 for high-quality reports. The timing of this patch is significant as it coincides with the implementation of the Cyber Resilience Act in Europe.
The act requires manufacturers to report actively exploited vulnerabilities within 24 hours of becoming aware. While Google patched the bug before the deadline, the new regulations will change how software companies handle security issues moving forward.