Google patches Chrome zero-day already under active exploitation
Google $GOOGL released an emergency patch for CVE-2026-85046, a high-severity (CVSS 8.8) Chrome bug already being exploited in the wild. The flaw lets an attacker execute code inside Chrome's sandbox from nothing more than a crafted webpage. It's the sixth actively exploited Chrome zero-day Google has fixed this year. Per The Hacker News / Security Affairs.
Google has patched a Chrome vulnerability, CVE-2026-85046 (CVSS 8.8), that attackers are already exploiting in the wild. The flaw is a type confusion bug in V8, Chrome's JavaScript and WebAssembly engine, that lets a remote attacker execute arbitrary code inside Chrome's sandbox using nothing more than a single crafted HTML page. Google $GOOGL has confirmed an exploit exists in the wild but has not disclosed how the attacks work or who is behind them. Security researcher Salvatore Gulizia (aka Serotav) reported the bug on August 4, 2026, and received a $1,000 bug bounty. This is the sixth actively exploited Chrome zero-day Google has fixed since the start of 2026, following flaws patched in February, March, April, and June. The fix ships in Chrome 152.0.7977.82/.83 for Windows, Mac and Linux; users of other Chromium-based browsers such as Edge, Brave and Vivaldi should update as patches arrive. Per The Hacker News / Security Affairs.