Google has released a critical security update for its Chrome web browser, addressing twelve vulnerabilities, including one that is currently being exploited by attackers. The most serious issue, identified as CVE-2026-85046, affects V8, the JavaScript engine that powers Chrome. This vulnerability allows a remote attacker to execute arbitrary code within the browser’s sandbox using a single malicious HTML page. The flaw was discovered by researcher Salvatore Gulizia, also known as Serotav, who was awarded $1,000 for reporting it. The vulnerability was reported on August 4, 2026, and has a CVSS score of 8.8, indicating a high level of risk.
The flaw stems from a type confusion error in the V8 compilers. Specifically, an array that should be assigned a generic data type is mistakenly given the type used for small integers. This mistake allows attackers to access and manipulate memory areas that should be restricted to the JavaScript heap used by the engine. Google confirmed that exploit code is circulating in the wild, though it did not provide specific details about the attacks or their impact.
In addition to CVE-2026-85046, the update fixes nine other high-severity vulnerabilities. These include a second issue in V8 related to a race condition, as well as bugs in components like Compositing, WebGL, DevTools, Skia, and CacheStorage. Two medium-severity vulnerabilities, which involve incorrect input validation and using resources that have already been released, are also addressed in the update. The patches are automatically applied through Chrome’s update system, accessible via the Help menu under "About Google Chrome."
The update is part of a growing trend of zero-day vulnerabilities being fixed in Chrome this year. CVE-2026-85046 is the sixth such vulnerability discovered in 2026, following CVE-2026-2441, CVE-2026-3909, CVE-2026-3910, CVE-2026-5281, and CVE-2026-11645. While Chrome users are automatically protected by this update, browsers based on Chromium, such as Microsoft Edge, Brave, Opera, and Vivaldi, will need to apply their own patches once they become available.
Google Issues Chrome Update to Fix 12 Vulnerabilities, Including One Already Exploited
AI-rewritten from original reportingHow it works
chrome-updatev8-enginecve-2026-85046zero-daysecurity-patch



