Google fixes the sixth actively exploited Chrome zero-day of 2026
Brief
Google patched 12 Chrome flaws, including an actively exploited V8 zero-day that could enable remote code execution through a crafted webpage.
Google released a Chrome security update fixing 12 vulnerabilities, including CVE-2026-85046 (CVSS score of 8.8), an actively exploited V8 type confusion flaw.
The bug affects Chrome’s JavaScript and WebAssembly engine and could let a remote attacker execute arbitrary code inside the browser sandbox by using a specially crafted HTML page.
“CVE-2026-85046: Type confusion in V8.” reads the advisory . “Google is aware that an exploit for CVE-2026-85046 exists in the wild.”
As usual, Google did not disclose technical details about the attacks exploiting this vulnerability or attribute them to any specific threat actor.
Security researcher Salvatore Gulizia, known as Serotav, reported the flaw on August 4, 2026, and received a $1,000 bug bounty.
