Google Patches Chrome Zero-Day Exploited by Hackers
Chrome’s V8 engine runs JavaScript and WebAssembly, making memory-safety defects in the component particularly sensitive. CVE-2026-85046 is a high-severity type-confusion flaw that could let a remote attacker execute arbitrary code inside Chrome’s sandbox through a specially crafted HTML page. Google has confirmed that an exploit exists in the wild, though it has not disclosed the attackers, targets or scale of the campaign, and has not linked it to cryptocurrency theft.
Google issued the security update on Sept. 3, 2026, addressing 12 vulnerabilities in total. The company is rolling out Chrome 152.0.7977.82/.83 for Windows and Mac and version 152.0.7977.82 for Linux. Distribution will be gradual, so users and corporate administrators should check for the release manually and restart the browser to activate it. The actively exploited flaw carries a CVSS score of 8.8 and is the sixth Chrome zero-day patched in 2026.
All Coverage
2 original reportsThe Backstory
The history behind this eventNo historical echoes for this signal
Subscribe to Mark Radar Weekly
Every Friday, the week's strongest signals in your inbox. Unsubscribe anytime.
If you search news on Google, you can set Mark Radar as a preferred source—our coverage will show up more often in your results. Set as preferred source on Google →