Chrome Zero-Day CVE-2026-85046: Patch Deadline Is Sept 18

September 18, 2026 is the date the U.S. Cybersecurity and Infrastructure Security Agency set for federal civilian agencies to finish patching CVE-2026-85046, a flaw in the V8 engine that powers Google Chrome. CISA added the bug to its Known Exploited Vulnerabilities catalog on September 4, one day after Google shipped a fix and confirmed that an exploit for it was already circulating.
Google's Chrome Releases post of September 3 describes the bug as a type confusion error in V8, the browser's JavaScript and WebAssembly engine, and lists it among 12 security fixes in Chrome 152.0.7977.82/.83 for Windows and macOS and 152.0.7977.82 for Linux. "Google is aware that an exploit for CVE-2026-85046 exists in the wild," the company wrote, without elaborating. The National Vulnerability Database scores it 8.8 out of 10, and its rating notes the attack can arrive across the network with no account or privileges, though the target does have to open a page the attacker controls.
The reach is wider than Chrome. CISA's catalog entry warns the flaw "could affect multiple web browsers that utilize Chromium, including, but not limited to, Google Chrome, Microsoft Edge, and Opera." For most readers the fix takes under a minute: Chrome downloads updates on its own but only finishes on restart, so open Help > About Google Chrome and click Relaunch. People on Edge, Opera, Brave or Vivaldi need the updated build from their own vendor.
Google credits Salvatore Gulizia, who works under the handle Serotav, with reporting the bug on August 4, 2026, and paid a $1,000 bounty. Gulizia later published a technical writeup, linked from the CVE's NVD record, explaining how the bug tricks V8 into mislabelling the contents of an array and how he turned that into arbitrary read and write access on the JavaScript heap. In the same writeup he says he chained the flaw with an already-known sandbox escape and submitted the result to v8CTF, Google's own exploit contest. Google has not said whether that work relates to the in-the-wild exploit it cited, and has released nothing about who was attacked or by whom. CISA marks known ransomware use as "Unknown". By The Hacker News's count, this was the sixth actively exploited Chrome zero-day Google patched in 2026 — and the run continued: on September 9 CISA added another Chromium V8 zero-day, CVE-2026-87491, to the same catalog, with its own deadline of September 23.
Sources
- Google Chrome ReleasesPrimary source
- CISA Known Exploited Vulnerabilities CatalogPrimary source
- NIST National Vulnerability DatabasePrimary source
- Salvatore Gulizia (Serotav) — technical writeupSecondary
- The Hacker NewsSecondary
Related
WordPress 7.1.1 Patches Click2Shell: One Link Installs a Theme
BragJack: One Extension Hijacked AI Agents in 5 Browsers
Google Says Gemini Hacked Three Real Companies in May Test
Microsoft Discloses CVSS 10.0 Azure AI Foundry Flaw, Already Fixed
Docker Sandboxes Flaw Rated 9.4 Let Code Escape to Mac Host
Plugin4Shell: 4 AI Coding Agents Hit, 2 Still Unpatched
Check Point Flaw Rated 9.8 Lets Attackers Run Code as Root
3 Linux Kernel Flaws Exploited; CISA Sets Sept. 21 Patch Deadline
Trending now
- Universal, Sony Sue Suno Again Over 60,202 Recordings
- China's CXMT Starts Mass Production of 11.95nm G5 DRAM
- Alibaba Open-Sources CT AI That Flags 146 Conditions
- Microsoft Discloses CVSS 10.0 Azure AI Foundry Flaw, Already Fixed
- Sharks Feed on Beached Whale in Jamaica; NEPA Warns Swimmers
- Plugin4Shell: 4 AI Coding Agents Hit, 2 Still Unpatched
- Anthropic Targets November IPO at About $2 Trillion Value
- 1,200 Gravity Readings Revive King Tut Hidden-Chamber Debate
Comments
No comments yet. Be the first.