Google Patches Chrome Zero-Day Already Exploited by Hackers

Google shipped an emergency Chrome update on September 3, 2026, to fix a security flaw that attackers are already using in real-world attacks, according to the company's Stable Channel release notes cited by Help Net Security and Cybersecurity News.
The bug, tracked as CVE-2026-85046, is a type confusion vulnerability in V8, Chrome's JavaScript and WebAssembly engine. It carries a CVSS severity score of 8.8 out of 10. According to Google's advisory, a remote attacker who convinces a victim to visit a specially crafted HTML page can trigger the bug to execute arbitrary code inside Chrome's sandbox.
"Google is aware that an exploit for CVE-2026-85046 exists in the wild," the company said, without disclosing further technical details about the attacks in order to limit the risk of copycat exploitation.
Why now: the fix landed in Chrome 152.0.7977.82/.83 for Windows and macOS, and 152.0.7977.82 for Linux, and is rolling out gradually over the coming days and weeks. Users won't get the patch until Chrome downloads and applies the update, which normally happens automatically but can be forced by opening chrome://settings/help and restarting the browser.
Why it matters: this is the sixth Chrome zero-day Google has patched in 2026, according to Help Net Security's tracking of the browser's security bulletins — underscoring how often V8's complex JavaScript engine keeps becoming a target for attackers. Because Chrome is the world's most used browser, a flaw that's already being exploited puts a large share of internet users at risk of having their browsing sessions hijacked or malware installed simply by loading a booby-trapped webpage.
The flaw was originally reported to Google on August 4, 2026, by security researcher Salvatore Gulizia, who goes by the handle Serotav online. Gulizia described the issue as a V8 compiler bug that causes an array containing PACKED_ELEMENTS to incorrectly receive the PACKED_SMI_ELEMENTS map, a mismatch that can be exploited to corrupt memory. Google paid Gulizia a $1,000 bug bounty for the report, according to Help Net Security.
Security researchers recommend that users of Chrome, and of Chromium-based browsers such as Edge, Brave and Opera that share the same V8 engine, check for updates immediately rather than waiting for the automatic rollout.
Related
OpenAI Agent Breached Medicare Portal; Australia Told 84 Days Later
996 Zyxel Switches Looted in 48 Countries; Patch Due Sept. 24
Attacks on WordPress RCE Flaw Rose Tenfold After Sept. 22 Fix
Arista VeloCloud Zero-Day at CVSS 10.0; Patch Due Sept. 25
Check Point: VPN Flaw Under Attack Since Sept. 12, Patch by Sept. 25
Malware Lets 4 AI Models Vote on Its Next Attack Move
Microsoft Shuts Down AI Phishing Service That Hit 12,000 Inboxes
F5 Patches Exploited BIG-IP Flaw; CISA Deadline Is Sept. 25
Trending now
- US-China Trade Truce Extended to Jan. 10 as Xi Visits
- Amoeba Breeds at 63°C, Past the 60°C Limit for Complex Life
- 996 Zyxel Switches Looted in 48 Countries; Patch Due Sept. 24
- Oracle Invokes Force Majeure on 2.45GW Stargate Data Center
- Diller Drops $18B MGM Bid; Stock Falls 9.5% to February Levels
- Taylor Swift Adds 4 Songs to ‘Showgirl’ in Sept. 25 Encore
- Attacks on WordPress RCE Flaw Rose Tenfold After Sept. 22 Fix
- Rivian Recalls 98,828 EVs Over Rearview Camera Fault
Comments
No comments yet. Be the first.