CVE Tools

Google warns of new Chrome zero-day flaw exploited in attacks

BleepingComputerBy Bill Toulas

Reported exploitedChromeV8

Our summary

Google has released updates for Chrome, upgrading desktop versions to 152.0.7977.82 and .83 on Windows/macOS and 152.0.7977.82 on Linux, to remediate an actively exploited high-severity zero-day vulnerability in the V8 engine. The flaw, identified as CVE-2026-85046, is a type confusion issue reported by researcher Salvatore Gulizia that could potentially lead to remote code execution via malicious JavaScript. This marks the sixth time Google has patched an in-the-wild Chrome exploit in 2026; users are advised to update promptly to protect their systems.

Read at BleepingComputer

BleepingComputer publishes this story on its own site; we link to it rather than reprint it.

Worried this affects your company?

Discuss a security assessment of your internet-facing systems. Scope agreed before testing.

Check my exposure

We use analytics cookies to see which pages and articles actually help people. Decline and none of them run — the site works the same. What we store