Google warns of new Chrome zero-day flaw exploited in attacks
AI Generated Image

Google warns of new Chrome zero-day flaw exploited in attacks

BleepingComputer technology

Key Points:

  • Google has released an update for Chrome (version 152.0.7977.82/.83) to fix a high-severity zero-day vulnerability (CVE-2026-85046) in its V8 JavaScript engine, which is actively exploited in the wild.
  • The flaw is a type confusion bug that could allow remote code execution via malicious JavaScript in a specially crafted HTML page, affecting Chrome’s sandboxed renderer process.
  • The update also patches 11 other vulnerabilities, including use-after-free and out-of-bounds memory issues across various Chrome components such as Crash Reporting, Network, and WebGL.
  • This marks the sixth actively exploited Chrome zero-day fixed by Google in 2026, with previous patches addressing critical vulnerabilities in V8, Skia, CSSFontFeatureValuesMap, and WebGPU implementations.
  • Users are urged to update Chrome promptly through Settings > About Chrome and restart the browser; similar updates are expected soon for Chrome-based browsers like Microsoft Edge, Brave, Opera, and Vivaldi.

Trending Business

Trending Technology

Trending Health