Google patches actively exploited Chrome zero-day (CVE-2026-85046)
Reported exploitedChromeV8Our summary
Google has addressed twelve security flaws in its browser, including a high-severity vulnerability in the V8 engine known as CVE-2026-85046. This bug is currently being leveraged by attackers to run arbitrary code within the browser's sandbox through malicious web content. The patch has been distributed in Chrome version 152.0.7977.82 and 152.0.7977.83 for desktop platforms. Users should ensure their browsers are updated to mitigate the risk of remote exploitation.
Help Net Security publishes this story on its own site; we link to it rather than reprint it.
Worried this affects your company?
Discuss a security assessment of your internet-facing systems. Scope agreed before testing.