CiberLATAMbywhalemate

Google patches Chrome for CVE-2026-85046

Google issued an emergency Chrome update fixing CVE-2026-85046, an actively exploited flaw in V8.

Whalemate Labs · AI-assisted researchPublished:3 min read

Google released an emergency security update for Chrome that fixes CVE-2026-85046, a high-severity V8 vulnerability that was already being actively exploited, according to several security sources. The patch covers Chrome Stable, Extended Stable, and Chrome for Android.

Google released an emergency security update for Chrome to fix CVE-2026-85046, a type-confusion vulnerability in V8 that security sources said was being actively exploited when the patch landed. The flaw was described as high severity and could let a crafted HTML page trigger arbitrary code execution inside Chrome's sandbox.

What exactly does the patch fix?

The update addresses CVE-2026-85046, a flaw in V8, Chrome's JavaScript and WebAssembly engine. The Hacker News reported that Google pushed the emergency patch on September 3, 2026, while UpGuard assigned it a CVSS score of 8.8 and described it as a bug that could lead to remote code execution within Chrome's sandboxed process after visiting a malicious page.

Google officially documented the CVE as a type-confusion vulnerability in V8 that was exploited in the wild. In the Chrome 152 release note, the company said, "Google is aware that an exploit for CVE-2026-85046 exists in the wild" and noted that the fix is being distributed through the Stable and Extended Stable channels, according to CVE Brief.

Which versions and platforms are covered?

The patch was included in Chrome Stable 152.0.7977.82 and .83 for Windows and macOS, and in 152.0.7977.82 for Linux, which means all desktop builds earlier than 152.0.7977.82 were marked vulnerable, according to Shattered.io and OpenCVE. CVE Brief also documented fixed builds for Chrome Extended Stable and Chrome for Android in the same 152.0.7977.82 branch.

The independent advisories cited in the material also say the vulnerability affects every platform where Chrome runs, including Windows, macOS, Linux, Android, and iOS. Ayine Djimi Consultants recommended urgently updating the entire corporate fleet to version 152.0.7977.82 or later and confirming deployment through endpoint management tools.

What did security agencies and firms say?

Several sources confirmed that CVE-2026-85046 was being actively exploited. Malwarebytes reported it in its September 3 coverage, and Telconet CSIRT said Google had released an emergency Chrome security update to fix a flaw being used in real-world attacks.

Qualys added that the update package bundled 12 security fixes, and that CVE-2026-85046 was the only confirmed zero-day in the set that was actively exploited. CISA also added the vulnerability to its Known Exploited Vulnerabilities catalog and set a mitigation deadline of September 18, 2026, instructing organizations to apply the patch before then.

What risk remains beyond Chrome?

The risk extends to other Chromium-based browsers that share the V8 engine, including Microsoft Edge, Brave, Opera, and Vivaldi, until they adopt the corrected V8 version, according to xhack.io. That same analysis warned that Chrome's staged update model means the fix does not reach every endpoint on the same day, and that effective mitigation only happens after the browser is restarted.

CVE Brief and OpenCVE agreed that all Google Chrome versions earlier than 152.0.7977.82 are affected by CVE-2026-85046, with the stable patch release in early September 2026 serving as the cutoff.

Sources

View all