Google Releases Chrome Update to Patch Actively Exploited V8 Zero-Day
- ID
- 21406
- Status
- summarized
- Published
- 04 Sep 2026, 3:18 PM
- Fetched
- 04 Sep 2026, 4:34 PM
- Provider
- The Hacker News
- Category
- security
- Original URL
- https://thehackernews.com/2026/09/google-releases-chrome-update-to-patch.html
- Source URL
- https://feeds.feedburner.com/TheHackersNews
Summary
- Score
- 6.0
- Created
- 04 Sep 2026, 4:34 PM
- Tags
- Audience
- developersvibe_coders
What happened
Google patched CVE-2026-85046, a high-severity V8 type confusion bug (CVSS 8.8) actively exploited in the wild, allowing remote code execution inside Chrome's sandbox via a crafted HTML page. The fix ships in Chrome 152.0.7977.82/.83 for Windows/macOS and 152.0.7977.82 for Linux, and this is the sixth actively exploited Chrome zero-day patched in 2026.
Why it matters
Update Chrome and any Chromium-based browser (Edge, Brave, Opera, Vivaldi) to the patched versions now — the exploit is active in the wild. For developers, the bug is a type confusion in V8's compilers where a PACKED_ELEMENTS array receives a PACKED_SMI_ELEMENTS map, enabling arbitrary read/write on the JavaScript heap, which is a notable detail for anyone studying engine internals or sandbox escape techniques.
Discussion angle
Why a $1,000 bounty for a actively-exploited V8 RCE zero-day feels mispriced, and what that says about the economics of browser bug hunting versus the impact of these flaws.