Google has released a Chrome update to patch a high-severity zero-day vulnerability that has been actively exploited in attacks, along with fixes for eleven other security issues. The company confirmed the exploit in an advisory, marking the sixth actively exploited bug it has resolved in Chrome this year. The update rolls out gradually, bringing the browser to version 152.0.7977.82/.83 on Windows and macOS, and 152.0.7977.82 on Linux.
The exploited flaw, tracked as CVE-2026-85046, is a type confusion issue in the V8 engine, Chrome's open-source JavaScript and WebAssembly component that compiles and executes website code. Researcher Salvatore Gulizia, who goes by the online handle "Serotav," reported the bug to Google. The company withheld technical details about the exploitation to give users and dependent projects time to install the fix.
Type confusion vulnerabilities allow software to incorrectly treat one type of object as another, enabling memory corruption. In the case of V8, a specially crafted HTML page carrying malicious JavaScript could trigger the flaw, potentially permitting remote code execution within Chrome's sandboxed renderer process. The vulnerability is classified as high severity rather than critical, but its confirmed in-the-wild exploitation elevates the urgency for users to update.
Beyond the zero-day, the Chrome update addresses nine other high-severity vulnerabilities, including use-after-free and out-of-bounds memory flaws across several components. Affected areas include Crash Reporting, Network, Compositing, WebGL, CacheStorage, DevTools, and Skia, as well as a race condition in V8. Google did not specify whether those additional issues were also exploited in attacks.
The patch is available through Chrome's standard update mechanism. Users on Windows, macOS, and Linux should navigate to Settings, then About Chrome, and wait for the update to download and install. A browser restart is required for the fixes to take effect. The rollout is gradual, so some users may not see the update immediately.
People using Chrome-based browsers, such as Microsoft Edge, Brave, Opera, and Vivaldi, are also advised to apply corresponding fixes when they become available, though updates for those applications may arrive a few days later. For U.S. users and businesses relying on Chrome or its derivatives for daily operations, the recommendation is to check for updates and restart the browser once the patch appears.
More cybersecurity news from TechManNews.







