Google Patches High-Severity Chrome Zero-Day as Attackers Exploit V8 Flaw
Google has released an emergency security update for Chrome after confirming that attackers are actively exploiting a high-severity vulnerability in the browser's V8 JavaScript and WebAssembly engine.
The vulnerability, tracked as CVE-2026-85046, is a type-confusion flaw that could allow a remote attacker to execute arbitrary code inside Chrome's sandboxed renderer process after a user visits a maliciously crafted webpage.
Google addressed the zero-day as part of a broader Chrome 152 security update containing 12 fixes. The patched desktop versions are Chrome 152.0.7977.82 and 152.0.7977.83 for Windows and macOS, and 152.0.7977.82 for Linux.