Chrome Zero-Day CVE-2026-85046 Actively Exploited
Google confirmed an exploit for CVE-2026-85046, a type confusion bug in Chrome's V8 engine, is already active in the wild. It is the sixth actively exploited Chrome zero-day patched in 2026.
Google has patched CVE-2026-85046, a type confusion vulnerability in V8, Chrome's JavaScript and WebAssembly engine, after confirming an exploit for the flaw already exists in the wild. A single crafted webpage can trigger the bug and run code inside Chrome's sandbox. Security researcher Salvatore Gulizia reported the underlying issue on August 4, 2026, and earned a ,000 bug bounty. Google has not disclosed who is behind the in-the-wild exploitation or who has been targeted. It is the sixth actively exploited Chrome zero-day Google has patched in 2026. The fix is rolling out in Chrome and to Chromium-based browsers including Edge and Brave. Users are advised to update via Settings > About Chrome and restart the browser.