Google warns of new Chrome zero-day flaw exploited in attacks

Google has issued a critical update to address an actively exploited high-severity vulnerability in its Chrome browser. The flaw, identified as CVE-2026-85046, is a type confusion issue that can allow attackers to corrupt memory and potentially execute malicious code within Chrome’s sandboxed environment.

The vulnerability was reported by security researcher Salvatore Gulizia, known online as “Serotav,” who also disclosed an existing exploit in the wild. Google has taken swift action to address the issue, updating Chrome to version 152.0.7977.82/.83 on Windows and macOS, and 152.0.7977.82 on Linux. The update is being rolled out gradually, so users may not see it immediately.

Type confusion flaws are a type of bug that causes software to misinterpret one type of object as another. This can lead to malicious code being executed, potentially allowing attackers to steal sensitive information or take control of the system. In this case, the V8 engine, Chrome’s open-source JavaScript and WebAssembly engine, is vulnerable to type confusion attacks.

The update also addresses nine other high-severity vulnerabilities in Chrome, including use-after-free and out-of-bounds memory flaws in various components such as Crash Reporting, Network, Compositing, WebGL, CacheStorage, DevTools, Skia, and V8. These types of bugs can be particularly damaging, as they allow attackers to access sensitive information or execute malicious code within the browser.

This is not an isolated incident – Google has patched six actively exploited bugs in Chrome since the start of the year. The frequency of these vulnerabilities highlights the importance of keeping software up-to-date and secure. Users are advised to apply the available update as soon as possible by going to Settings > About Chrome and waiting for the update to download and install.

After applying the update, a browser restart is required for the fixes to take effect. Similar actions should be taken by users of Chrome-based browsers, including Microsoft Edge, Brave, Opera, and Vivaldi. While these browsers are also affected by the vulnerability, it may take a couple of extra days for fixes to arrive on those apps.

In conclusion, this latest development serves as a reminder that even the most popular software can be vulnerable to attacks. As users, we must remain vigilant and ensure our systems are up-to-date with the latest security patches. By taking proactive steps to secure our browsers and software, we can significantly reduce the risk of falling victim to cyber threats.


Source: Bleeping Computer — 2026-09-04