Cybersecurity

Google Patches Chrome Zero-Day Already Exploited by Hackers

Published 2 min readBy NewUJ Editorial Desk

Updated new information added

Google Patches Chrome Zero-Day Already Exploited by Hackers
0 0
XWhatsAppTelegramLinkedIn

Google shipped an emergency Chrome update on September 3, 2026, to fix a security flaw that attackers are already using in real-world attacks, according to the company's Stable Channel release notes cited by Help Net Security and Cybersecurity News.

The bug, tracked as CVE-2026-85046, is a type confusion vulnerability in V8, Chrome's JavaScript and WebAssembly engine. It carries a CVSS severity score of 8.8 out of 10. According to Google's advisory, a remote attacker who convinces a victim to visit a specially crafted HTML page can trigger the bug to execute arbitrary code inside Chrome's sandbox.

"Google is aware that an exploit for CVE-2026-85046 exists in the wild," the company said, without disclosing further technical details about the attacks in order to limit the risk of copycat exploitation.

Why now: the fix landed in Chrome 152.0.7977.82/.83 for Windows and macOS, and 152.0.7977.82 for Linux, and is rolling out gradually over the coming days and weeks. Users won't get the patch until Chrome downloads and applies the update, which normally happens automatically but can be forced by opening chrome://settings/help and restarting the browser.

Why it matters: this is the sixth Chrome zero-day Google has patched in 2026, according to Help Net Security's tracking of the browser's security bulletins — underscoring how often V8's complex JavaScript engine keeps becoming a target for attackers. Because Chrome is the world's most used browser, a flaw that's already being exploited puts a large share of internet users at risk of having their browsing sessions hijacked or malware installed simply by loading a booby-trapped webpage.

The flaw was originally reported to Google on August 4, 2026, by security researcher Salvatore Gulizia, who goes by the handle Serotav online. Gulizia described the issue as a V8 compiler bug that causes an array containing PACKED_ELEMENTS to incorrectly receive the PACKED_SMI_ELEMENTS map, a mismatch that can be exploited to corrupt memory. Google paid Gulizia a $1,000 bug bounty for the report, according to Help Net Security.

Security researchers recommend that users of Chrome, and of Chromium-based browsers such as Edge, Brave and Opera that share the same V8 engine, check for updates immediately rather than waiting for the automatic rollout.

Report / request removal

Related

Comments

No comments yet. Be the first.