
Google released a fix for CVE-2026-85046, a critical type confusion vulnerability in the V8 engine that is currently being exploited in the wild by remote attackers.
The patch is included in Chrome version 152.0.7977.82/.83 for Windows and macOS, and 152.0.7977.82 for Linux, following a report by researcher Salvatore Gulizia on August 4, 2026.
This vulnerability, which carries a CVSS score of 8.8, marks the sixth Chrome zero-day patched by Google in 2026 and allows arbitrary code execution within the browser sandbox.