Google issues an emergency Chrome update to fix an actively exploited zero-day vulnerability.

The V8 zero-day (CVE-2026-85046) was reported by security researcher Salvatore Gulizia (aka “Serotav”) on Aug. 4, 2026, and Google awarded a $1,000 bug bounty for the report.
In the non-emergency Chrome 152 patch cycle, Google described the two critical use-after-free issues with specific CVEs: CVE-2026-84353 in Shared Tab Groups and CVE-2026-84352 in WebGL.
Google’s advisory said only three of the 26 Chrome vulnerabilities were reported by external researchers, and it did not disclose any bug bounty reward details for those findings.
For the broader September 1 security update (Chrome 152.0.7977.75/.76 on Windows/macOS; 152.0.7977.75 on Linux), Google indicated that details about some vulnerabilities may remain restricted until a significant portion of users have installed the fixes.
Google rushed out an emergency Chrome patch to fix a critical zero-day flaw that hackers are already exploiting Yahoo News. The V8 type confusion bug, tracked as CVE-2026-85046, lets attackers run malicious code directly on a user's computer via crafted web content Forbes. The emergency update rolled out gradually starting with Chrome 152.0.7977.82 and 152.0.7977.83 on desktop Hot Hardware.
In the same patch cycle, Google also fixed 26 other Chrome vulnerabilities, including two critical use-after-free bugs in Shared Tab Groups and WebGL Yahoo News. Security researcher Salvatore Gulizia reported the zero-day on August 4 and earned a $1,000 bug bounty Hot Hardware. Users should update immediately — the flaw poses extreme risk for remote code execution and privilege escalation Yahoo News.
The V8 engine vulnerability stems from a type confusion error — the browser misinterprets what kind of data a variable holds in memory Hot Hardware. Attackers use this mistake to break out of Chrome's sandbox, the safety wall that normally isolates the browser from the rest of your system Yahoo News. Once inside, they can execute arbitrary code with the same permissions as the browser process Forbes.
Google did not wait for its normal monthly patch schedule. The company pushed Chrome 152.0.7977.82 and 152.0.7977.83 to Windows, macOS, and Linux users as an emergency release Yahoo News. The rollout happened gradually to avoid overwhelming servers, but affected billions of Chrome users worldwide Hot Hardware. Chrome for iPhone and iPad received version 153 with routine stability improvements, though users should apply any available updates Yahoo News.
Beyond the active zero-day, Google addressed 26 additional vulnerabilities in Chrome 152 Yahoo News. Two stood out as critical: a use-after-free flaw in Shared Tab Groups (CVE-2026-84353) and another in WebGL (CVE-2026-84352) Yahoo News. The remaining issues ranged from high to low severity, covering denial of service, information disclosure, and security bypass pathways Yahoo News. Only three vulnerabilities came from external researchers; Google's own teams found the rest Yahoo News.
Active exploitation means attackers are using this flaw against real people today Forbes. A malicious website could silently compromise your system the moment you visit it Yahoo News. Google warned that some vulnerability details will stay hidden until a large share of users patch, preventing attackers from learning new tricks Yahoo News. Delaying the update puts you at risk for data theft, credential theft, and malware installation.
Publishers
18
Articles
1
Reach
19