- Google patched 12 Chrome vulnerabilities on September 4, 2026, including one actively exploited zero-day.
- The high-severity flaw, CVE-2026-85046, is a type confusion bug in the V8 JavaScript engine that allows arbitrary code execution.
- Security researcher Salvatore Gulizia discovered and reported the bug, receiving a $1,000 bounty for responsible disclosure.
On September 4, 2026, Google released security updates for Chrome to patch 12 vulnerabilities, including one actively exploited in the wild. The high-severity issue, tracked as CVE-2026-85046, is a type confusion bug in Chrome’s V8 JavaScript and WebAssembly engine.
According to the official description, “Type confusion in V8 in Google Chrome prior to 152.0.7977.82 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page.” Security researcher Salvatore Gulizia discovered and reported the flaw on August 4, 2026, and received a $1,000 bug bounty for responsible disclosure.
In his detailed write-up, Gulizia described it as a “V8 bug in the compilers that leads to an array containing PACKED_ELEMENTS to receive the map PACKED_SMI_ELEMENTS, this can be turned into arbitrary read/write on the JavaScript heap.” Google acknowledged that an exploit for CVE-2026-85046 exists in the wild but withheld attack details to allow users time to update.
Consequently, this marks the sixth actively exploited Chrome zero-day patched in 2026, following CVE-2026-2441, CVE-2026-3909, CVE-2026-3910, CVE-2026-5281, and CVE-2026-11645. Users should update to Chrome versions 152.0.7977.82/.83 on Windows and macOS, and 152.0.7977.82 on Linux, by navigating to More > Help > About Google Chrome and selecting Relaunch. Users of other Chromium-based browsers like Microsoft Edge, Brave, Opera, and Vivaldi are also advised to apply fixes as they become available.
✅ Follow BITNEWSBOT on Telegram, Facebook, LinkedIn, X.com, and Google News for instant updates.
