Google Patches Critical Chrome Security Flaw Affecting Billions of Users

Google Patches Critical Chrome Security Flaw Affecting Billions of Users

Google has released security updates for Chrome to address 12 vulnerabilities, including a critical zero-day flaw that is actively being exploited by attackers. The vulnerability, tracked as CVE-2026-85046 with a CVSS score of 8.8, is a type confusion issue in V8, Chrome's JavaScript and WebAssembly engine. The flaw allows remote attackers to execute arbitrary code within the browser's sandbox through a specially crafted HTML page. Security researcher Salvatore Gulizia discovered and reported the bug on August 4, 2026, earning a one thousand dollar bounty from Google for the responsible disclosure.

According to Gulizia's technical analysis, the vulnerability involves a compiler bug in V8 that causes an array containing PACKED_ELEMENTS to incorrectly receive the PACKED_SMI_ELEMENTS map, which can then be exploited to achieve arbitrary read and write capabilities on the JavaScript heap. Google has confirmed that exploits for this vulnerability exist in the wild but has declined to share details about the attacks or threat actors involved. This deliberate withholding of information is a standard practice designed to give users time to apply security patches before additional attackers can weaponize the flaw.

This latest zero-day brings the total count to six actively exploited Chrome vulnerabilities that Google has patched since the start of 2026. The other five are CVE-2026-2441, CVE-2026-3909, CVE-2026-3910, CVE-2026-5281, and CVE-2026-11645. Users should immediately update Chrome to version 152.0.7977.82 or 83 on Windows and macOS, or version 152.0.7977.82 on Linux. Updates can be applied by navigating to More, then Help, then About Google Chrome and selecting Relaunch.

The U.S. Cybersecurity and Infrastructure Security Agency has added CVE-2026-85046 to its Known Exploited Vulnerabilities catalog on September 4, 2026, mandating that Federal Civilian Executive Branch agencies apply the patches by September 18, 2026. Users of Chromium-based browsers such as Microsoft Edge, Brave, Opera, and Vivaldi should also install security updates as they become available from their respective vendors to ensure protection against this actively exploited vulnerability.

Stay secure — stay Wavasec. 🔐