The Maivia Gazette

Verified AI news, every morning

Security

Google patches actively exploited V8 zero-day in Chrome

CVE-2026-85046 is a type confusion bug in the JavaScript engine, fixed alongside eleven other vulnerabilities in a gradual rollout.

A cracked glass browser pane being sealed by a small glowing wrench.
AI-generated illustration, not event photography.

Evidence: Official disclosure. Security stories run only with a named disclosure or independent reporting behind them.

Google has shipped a Chrome update that fixes a high-severity zero-day in the V8 JavaScript and WebAssembly engine that is being exploited in the wild. The flaw, tracked as CVE-2026-85046, is a type confusion bug and was reported by researcher Salvatore Gulizia, who goes by "Serotav." Google's advisory states that the company is aware an exploit exists in the wild, but it has withheld technical details to give users and dependent projects time to update. Type confusion bugs cause software to treat one kind of object as another, which can corrupt memory. Because V8 executes code from websites, the flaw could be triggered by a crafted HTML page with malicious JavaScript, potentially enabling remote code execution inside Chrome's sandboxed renderer process. The update moves Chrome to version 152.0.7977.82 or .83 on Windows and macOS and 152.0.7977.82 on Linux, and is rolling out gradually. It also addresses eleven other vulnerabilities, including nine rated high severity, covering use-after-free and out-of-bounds memory issues in components such as Crash Reporting, Network, Compositing, WebGL, CacheStorage, DevTools and Skia. Anyone running Chrome or a Chromium-based browser should confirm they are on the patched build, since attackers already have a working exploit.

Sources

  1. BleepingComputerGoogle warns of new Chrome zero-day flaw exploited in attacksPublished · fetched

Also in this edition