Google's Chrome stable update on September 3 closed CVE-2026-85046, a flaw that attackers were already using. The bug sits in V8, Chrome's JavaScript engine, and opening a crafted page is enough to trigger code execution. It is the sixth Chrome zero-day confirmed under active attack in 2026.

The bug is a type confusion in V8

CVE-2026-85046 is a type confusion flaw in V8, the JavaScript and WebAssembly engine inside Chrome. Type confusion happens when a piece of data is handled as a different type than it actually is. If a value stored as an integer is later read as a pointer, an attacker can reach memory the program never meant to expose, and that reach can be turned into arbitrary code execution. Engines like V8, which rewrite code at runtime to make it faster, tend to open brief windows where an optimization's assumptions no longer match the real type. That makes them a favorite target.

Google rates the flaw High, with a CVSS score of 8.8. Security researcher Salvatore Gulizia reported it to Google on August 4. The fix shipped in stable versions 152.0.7977.82 and 152.0.7977.83 for Windows and macOS, and 152.0.7977.82 for Linux. The same release carried 12 security fixes in total.

How the attack works, and why the clock matters

The setup is simple. A user opens an HTML page prepared by the attacker, a script on that page hits the V8 defect, and code runs inside Chrome's sandbox. A link in an email or a message, or a script slipped into an ad slot, is enough to get there.

Because the code stays inside the sandbox, this single bug does not hand over the whole operating system. In real campaigns, though, a flaw like this is normally chained with a second one that escapes the sandbox. Leaving the first door open buys very little, and Google has already confirmed that working exploit code exists.

CISA added the vulnerability to its Known Exploited Vulnerabilities catalog on September 4 and set September 18 as the remediation deadline for federal civilian agencies. The deadline formally applies to government systems, but private organizations often use the KEV listing as a signal for how urgently to patch.

Three of this year's six were in V8

The six Chrome zero-days confirmed under active exploitation in 2026 are CVE-2026-2441, CVE-2026-3909, CVE-2026-3910, CVE-2026-5281, CVE-2026-11645 and now CVE-2026-85046. Three of them were in V8, including CVE-2026-11645, the fifth of the year, which was an out-of-bounds read and write.

The concentration is not surprising. V8 executes code supplied by a remote party the moment a page loads, which makes it the closest execution surface an attacker can reach. Its optimization pipeline is also complex enough to leave logic gaps behind. All six flaws landing on the same CVSS 8.8 score suggests the attack patterns look broadly alike.

Checking your own build

Chrome updates itself by default, but the patch only takes effect after a restart. You can check the version and trigger the update from the page that opens when you enter this address.

chrome://settings/help

If the version shown is 152.0.7977.82 or later, you are covered. If it is older, the download starts on that page and applies once you click the relaunch button.

Chrome is not the only thing to check. Microsoft Edge, Brave, Vivaldi and Opera are built on Chromium and ship the same V8 engine, so each vendor's own update has to be applied separately. Patching Chrome alone does not settle it.

Summary

Google fixed CVE-2026-85046, an actively exploited type confusion flaw in V8, with Chrome 152.0.7977.82 and 152.0.7977.83 on September 3. The flaw is rated High at CVSS 8.8, and simply opening a crafted page can lead to code execution inside the sandbox. CISA added it to the KEV catalog on September 4 and gave federal agencies until September 18 to remediate. It is the sixth zero-day of 2026, and three of those six were in V8. Restart Chrome, confirm the build is 152.0.7977.82 or newer, and update any other Chromium-based browsers at the same time.