Google released emergency security updates on September 4, 2026, to patch a high-severity zero-day vulnerability in Chrome tracked as CVE-2026-85046. The flaw, which was actively exploited in the wild, affected the V8 JavaScript and WebAssembly engine and could allow remote attackers to execute arbitrary code inside the browser sandbox.
The vulnerability is a type confusion bug that enables a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. Google confirmed in a Thursday security advisory that it is aware that an exploit for CVE-2026-85046 exists in the wild, though the company has withheld specific technical details about the attacks to prevent further exploitation while users update their software. The flaw has been assigned a CVSS score of 8.8.
V8 Engine Flaw and the $1,000 Bounty
The security defect was discovered and reported on August 4, 2026, by researcher Salvatore Gulizia, also known as Serotav. For the responsible disclosure, Google awarded Gulizia a $1,000 bug bounty.
According to a detailed write-up by Gulizia, the root cause is a compiler error within the V8 engine.
“V8 bug in the compilers that leads to an array containing PACKED_ELEMENTS to receive the map PACKED_SMI_ELEMENTS, this can be turned into arbitrary read/write on the JavaScript heap.”
Salvatore Gulizia, Security Researcher
Gulizia further noted that the bug was present in both the Maglev and Turbofan components. Because type confusion bugs cause software to treat data as the wrong type, they can create severe memory safety problems, potentially allowing an attacker to manipulate the browser’s memory via malicious websites, phishing links, or compromised advertisements. Type confusion vulnerabilities are described as memory corruption bugs that could lead to crashes, remote code execution, and other malicious behavior.
Required Versions for Windows, macOS, and Linux
The security defect was resolved in the following versions:

- Windows and macOS: 152.0.7977.82/.83
- Linux: 152.0.7977.82
The update is rolling out over the coming days and weeks. Users can manually trigger the update by navigating to More > Help > About Google Chrome and selecting Relaunch. Other addressed issues include incomplete cleanup, improper resource exposure, and type confusion issues.
The risk extends beyond official Google Chrome installations. Users of other Chromium-based browsers—including Brave, Microsoft Edge, Opera, and Vivaldi—are advised to apply fixes as they become available from their respective developers.
A Growing Pattern of 2026 Zero-Days
CVE-2026-85046 marks the sixth actively exploited zero-day Google has patched since the start of 2026.

| Date | CVE ID | Vulnerability Type / Component |
|---|---|---|
| February 2026 | CVE-2026-2441 | Use after free in CSS |
| March 2026 | CVE-2026-3909 | Out-of-bounds write in Skia 2D graphics library |
| March 2026 | CVE-2026-3910 | V8 JavaScript/WebAssembly engine flaw |
| April 2026 | CVE-2026-5281 | Use-after-free in Dawn (WebGPU) |
| June 2026 | CVE-2026-11645 | Out-of-bounds memory access in V8 |
| September 2026 | CVE-2026-85046 | Type confusion in V8 |
The recurrence of V8 engine flaws is particularly notable, with three of the six zero-days this year targeting the same JavaScript and WebAssembly engine.
The Stakes of Sandbox Escapes
While the CVE-2026-85046 flaw allows for the execution of arbitrary code, it is currently limited to the browser sandbox. The sandbox is a security boundary designed to prevent malicious code from accessing the rest of the operating system.
However, the ability to achieve arbitrary read/write on the JavaScript heap is a critical first step in a larger attack chain.
