Google has just released a crucial update for its Chrome browser, patching a whopping 12 vulnerabilities – including a sixth zero-day exploit this year. The update, which affects versions 152 of Chrome, addresses a critical vulnerability that was being actively exploited by attackers.
The high-severity bug, tracked as CVE-2026-85046, is a type confusion issue in Chrome’s V8 JavaScript and WebAssembly engine. It allows hackers to perform remote read/write operations via crafted HTML pages, potentially leading to crashes, remote code execution, or other malicious behavior. Type confusion vulnerabilities are memory corruption bugs that can have serious consequences for users.
According to Google’s advisory, the company is aware that an exploit for CVE-2026-85046 exists in the wild, and it’s urging users to update their browser as soon as possible. The patch was developed by a security researcher named Salvatore Gulizia, who received a $1,000 bug bounty reward for reporting the vulnerability.
The update addresses nine other high-severity bugs, including out-of-bounds read/write, incomplete cleanup, use-after-free, and type confusion issues. Three of these vulnerabilities were reported by external researchers. Additionally, Google fixed two medium-severity improper input validation and use-after-free weaknesses.
It’s worth noting that this is the sixth Chrome zero-day exploit patched in 2026 alone. The other five exploits are CVE-2026-2441, CVE-2026-3909, CVE-2026-3910, CVE-2026-5281, and CVE-2026-11645.
The update is available for Windows, macOS, and Linux users, with Chrome versions 152.0.7977.82/.83 being patched on these platforms.
For those who use Chrome as their primary browser, this update should be treated as a high-priority patch. Updating your browser to the latest version will not only protect you from CVE-2026-85046 but also fix other vulnerabilities that could put your online security at risk.
Source: SecurityWeek — 2026-09-04