Google Fixes Actively Exploited V8 Bug in Chrome

Google released a Chrome update fixing the high-severity CVE-2026-85046 vulnerability in V8. CISA has added it to its Known Exploited Vulnerabilities catalog.

Chrome CVE-2026-85046 is fixed in a new stable browser update from Google. It is a high-severity type confusion vulnerability in the V8 JavaScript engine, for which Google confirmed the existence of an exploit in the wild. On September 4, the U.S. agency CISA added it to the Known Exploited Vulnerabilities (KEV) catalog, which includes flaws with evidence of active exploitation.

Google updated Chrome’s stable channel on September 3, 2026. It released version 152.0.7977.82/.83 for Windows and macOS, while Linux received version 152.0.7977.82. The update is being rolled out gradually and, according to Google, may take days to weeks.

Chrome CVE-2026-85046 Fix Addresses a V8 Bug

The CVE-2026-85046 vulnerability is located in V8, a Chromium component that processes JavaScript and WebAssembly. Google classifies it as a high-severity type confusion flaw.

The vulnerability is fixed in version 152.0.7977.82 and later. Google’s release includes a total of 12 security fixes, with CVE-2026-85046 being particularly important because of confirmed exploitation.

CISA Adds the Bug to KEV

CISA added CVE-2026-85046 to its Known Exploited Vulnerabilities catalog on September 4. The inclusion is based on evidence of active exploitation and confirms that this is not merely a theoretical risk.

Google has not disclosed who is exploiting the vulnerability, what targets the attacks focused on, or the exploit’s technical details. A connection between the flaw and a specific attack campaign or users in Slovakia has also not been confirmed.

What Users and Administrators Should Do

Users and administrators should update Chrome to the fixed stable release. No publicly known alternative mitigation without updating has been confirmed.

In the coming days, it will be important to watch whether Google adds information about the attacks or exploit chain after the fix is rolled out more broadly. It will also be necessary to monitor whether related fixes are released for other Chromium-based browsers and whether fixed versions are confirmed for additional platforms or enterprise Chrome channels.

Sources

  • Chrome Releases – Google confirms the fixed versions, CVE-2026-85046, its high severity, the 12 fixes in the release, and the existence of an exploit in the wild.
  • CISA – CISA confirms that CVE-2026-85046 was added to the KEV catalog on September 4, 2026, based on evidence of active exploitation.
  • GitHub Advisory Database – The entry states that this is a type confusion vulnerability in V8 in Google Chrome before fixed version 152.0.7977.82.

Verified and updated: 09/05/2026 21:21

Sharing