Today's cybersecurity headlines are brought to you by ThreatPerspective


Ethical Hacking News

Google Releases Chrome Update to Patch Actively Exploited V8 Zero-Day Vulnerability



Google has released a security update for Chrome to address a critical vulnerability that has been actively exploited in the wild. The update patches 12 vulnerabilities, including a high-severity zero-day vulnerability that allows a remote attacker to execute arbitrary code. Users are advised to update their Chrome browser to ensure optimal protection and to keep their software up-to-date to prevent exploitation of zero-day vulnerabilities.

  • Google has released a security update to address a critical vulnerability in Chrome, CVE-2026-85046, that has been actively exploited in the wild.
  • 12 vulnerabilities are patched in the update, including one high-severity zero-day vulnerability.
  • Security researcher Salvatore Gulizia discovered the vulnerability and was awarded a $1,000 bug bounty for responsible disclosure.
  • Users are advised to update their Chrome browser to version 152.0.7977.82/.83 for Windows and macOS, and 152.0.7977.82 for Linux.
  • Other Chromium-based browsers, such as Microsoft Edge and Brave, should apply fixes as soon as they become available.



  • Google has recently released a security update for its Chrome browser to address a critical vulnerability that has been actively exploited in the wild. The update patches 12 vulnerabilities, including one that has been identified as a high-severity zero-day vulnerability, tracked as CVE-2026-85046. This vulnerability has been described as a type confusion bug in V8, Chrome's JavaScript and WebAssembly engine, which allows a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page.

    The discovery of this vulnerability was credited to security researcher Salvatore Gulizia, also known as Serotav, who discovered and reported the flaw on August 4, 2026. Gulizia was awarded a bug bounty of $1,000 for responsible disclosure of the vulnerability. In a separate blog post detailing the issue, Gulizia described it as a "V8 bug in the compilers that leads to an array containing PACKED_ELEMENTS to receive the map PACKED_SMI_ELEMENTS, this can be turned into arbitrary read/write on the JavaScript heap."

    Google acknowledged that an exploit for CVE-2026-85046 exists in the wild and has taken steps to address the vulnerability. The latest development marks the sixth actively exploited Chrome zero-day since the start of the year, following CVE-2026-2441, CVE-2026-3909, CVE-2026-3910, CVE-2026-5281, and CVE-2026-11645. Users are advised to update their Chrome browser to versions 152.0.7977.82/.83 for Windows and Apple macOS, and 152.0.7977.82 for Linux to ensure optimal protection.

    In addition to the Chrome update, Google has also advised users of other Chromium-based browsers, such as Microsoft Edge, Brave, Opera, and Vivaldi, to apply the fixes as and when they become available. The company has emphasized the importance of keeping software up-to-date to prevent exploitation of zero-day vulnerabilities.

    The discovery of this vulnerability highlights the ongoing threat of zero-day exploits and the importance of responsible disclosure by security researchers. It also underscores the need for software companies to prioritize security and provide timely updates to patch vulnerabilities. As AI-powered attacks continue to accelerate, it is essential for organizations to take proactive steps to strengthen their security posture and stay ahead of emerging threats.



    Related Information:
  • https://www.ethicalhackingnews.com/articles/Google-Releases-Chrome-Update-to-Patch-Actively-Exploited-V8-Zero-Day-Vulnerability-ehn.shtml

  • https://thehackernews.com/2026/09/google-releases-chrome-update-to-patch.html

  • https://thehackernews.com/2025/09/google-patches-chrome-zero-day-cve-2025.html

  • https://nvd.nist.gov/vuln/detail/CVE-2026-85046

  • https://www.cvedetails.com/cve/CVE-2026-85046/

  • https://nvd.nist.gov/vuln/detail/CVE-2026-2441

  • https://www.cvedetails.com/cve/CVE-2026-2441/

  • https://nvd.nist.gov/vuln/detail/CVE-2026-3909

  • https://www.cvedetails.com/cve/CVE-2026-3909/

  • https://nvd.nist.gov/vuln/detail/CVE-2026-3910

  • https://www.cvedetails.com/cve/CVE-2026-3910/

  • https://nvd.nist.gov/vuln/detail/CVE-2026-5281

  • https://www.cvedetails.com/cve/CVE-2026-5281/

  • https://nvd.nist.gov/vuln/detail/CVE-2026-11645

  • https://www.cvedetails.com/cve/CVE-2026-11645/


  • Published: Fri Sep 4 03:49:37 2026 by llama3.2 3B Q4_K_M













    © Ethical Hacking News . All rights reserved.

    Privacy | Terms of Use | Contact Us