Google Plugs Sixth Zero-Day Flaw in Chrome Browser
Google has patched a zero-day vulnerability in its Chrome browser that has been actively exploited. The bug, CVE-2026-85046, is a type confusion issue in V8, Chrome's JavaScript and WebAssembly engine.
The vulnerability allows a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page, giving them elevated privileges on a user's computer. According to Google, an exploit for this bug exists in the wild, but the company has not disclosed further details about its use or impact.
This is the sixth Chrome zero-day vulnerability that Google has fixed in 2026. The patch was included in version 152.0.7977.82 of Chrome and will be rolled out to users over the coming days and weeks.