Cybersecurity

Chrome Zero-Day CVE-2026-85046: Patch Deadline Is Sept 18

Published 2 min readBy NewUJ Editorial Desk

Updated new information added

Chrome Zero-Day CVE-2026-85046: Patch Deadline Is Sept 18
0 0
XWhatsAppTelegramLinkedIn

September 18, 2026 is the date the U.S. Cybersecurity and Infrastructure Security Agency set for federal civilian agencies to finish patching CVE-2026-85046, a flaw in the V8 engine that powers Google Chrome. CISA added the bug to its Known Exploited Vulnerabilities catalog on September 4, one day after Google shipped a fix and confirmed that an exploit for it was already circulating.

Google's Chrome Releases post of September 3 describes the bug as a type confusion error in V8, the browser's JavaScript and WebAssembly engine, and lists it among 12 security fixes in Chrome 152.0.7977.82/.83 for Windows and macOS and 152.0.7977.82 for Linux. "Google is aware that an exploit for CVE-2026-85046 exists in the wild," the company wrote, without elaborating. The National Vulnerability Database scores it 8.8 out of 10, and its rating notes the attack can arrive across the network with no account or privileges, though the target does have to open a page the attacker controls.

The reach is wider than Chrome. CISA's catalog entry warns the flaw "could affect multiple web browsers that utilize Chromium, including, but not limited to, Google Chrome, Microsoft Edge, and Opera." For most readers the fix takes under a minute: Chrome downloads updates on its own but only finishes on restart, so open Help > About Google Chrome and click Relaunch. People on Edge, Opera, Brave or Vivaldi need the updated build from their own vendor.

Google credits Salvatore Gulizia, who works under the handle Serotav, with reporting the bug on August 4, 2026, and paid a $1,000 bounty. Gulizia later published a technical writeup, linked from the CVE's NVD record, explaining how the bug tricks V8 into mislabelling the contents of an array and how he turned that into arbitrary read and write access on the JavaScript heap. In the same writeup he says he chained the flaw with an already-known sandbox escape and submitted the result to v8CTF, Google's own exploit contest. Google has not said whether that work relates to the in-the-wild exploit it cited, and has released nothing about who was attacked or by whom. CISA marks known ransomware use as "Unknown". By The Hacker News's count, this was the sixth actively exploited Chrome zero-day Google patched in 2026 — and the run continued: on September 9 CISA added another Chromium V8 zero-day, CVE-2026-87491, to the same catalog, with its own deadline of September 23.

Sources

Report / request removal

Related

Comments

No comments yet. Be the first.