Google Patches Actively Exploited Chrome Zero-Day Flaw in V8 Engine
Google has released an emergency security update for Chrome to address CVE-2026-85046, a critical type confusion vulnerability in the V8 JavaScript engine that is being actively exploited in the wild. The flaw allows a remote attacker to trigger arbitrary code execution within the browser sandbox by directing a user to a specially crafted HTML page. CISA has added the vulnerability to its Known Exploited Vulnerabilities catalog, signaling urgency for organizations to act. Users on Windows and macOS should update to Chrome version 152.0.7977.82 or 152.0.7977.83, while Linux users should update to 152.0.7977.82, and restart the browser to complete the patch. Operators of Chromium-based browsers are also advised to check for available updates and restrict access to untrusted sites in the interim.
This is an AI-generated summary. ShortSingh links to the original source for the complete article.


Discussion (0)
Log in to join the discussion and vote.
Log in