CYBERSECURITY

Google Patches Sixth Chrome Zero-Day of 2026

Google Patches Sixth Chrome Zero-Day of 2026

How This Fits Into Chrome’s 2026 Threat Landscape

Google released Chrome 152 on Thursday, addressing 12 security flaws including an actively exploited zero-day vulnerability. The update resolves a high-severity type confusion bug in the V8 JavaScript and WebAssembly engine, tracked as CVE-2026-85046. Security researcher Salvatore Gulizia reported the flaw and received a $1,000 bounty. The patch is now available for desktop and mobile users worldwide.

Details on the V8 Engine Flaw The type confusion vulnerability allowed attackers to execute arbitrary code by tricking Chrome into misidentifying object types during JavaScript compilation. Exploitation could lead to full system compromise if combined with other weaknesses. Gulizia discovered the issue during routine security testing and submitted it through Google’s Vulnerability Reward Program. Google confirmed the bug was being used in limited targeted attacks before the patch rollout.

Are Users Still at Risk After the Update?

This marks the sixth zero-day patched in Chrome this year, reflecting ongoing pressure from sophisticated threat actors. Google has accelerated its release cycle for critical fixes, reducing average response time to under 15 days. The company notes that 70% of 2026 Chrome zero-days have involved the V8 engine, prompting increased fuzzing and code hardening efforts. Engineers are now prioritizing runtime type checks in JavaScript optimization pipelines.

No, once Chrome 152 is installed, the specific CVE-2026-85046 exploit path is closed. Google emphasizes that automatic updates protect most users within 48 hours of release. However, organizations using delayed deployment policies should verify patch completion across all endpoints. The company urges administrators to check Chrome’s built-in safe browsing dashboard for confirmation of update status.

How do I know if my Chrome is updated to version 152? Check the version number in Settings > About Chrome; it should display 152.0.7901.0 or higher for the patch to be active.

Frequently Asked Questions

Was this zero-day used in widespread attacks? Google states the exploitation was limited to targeted campaigns, not broad-based internet scanning or mass malware distribution.

Can the V8 type confusion flaw affect other Chromium-based browsers? Yes, browsers like Edge, Brave, and Opera based on Chromium 152 or earlier are also vulnerable unless they have applied the same patch.

Content written by Daniel Cross for tech-site.news editorial team, AI-assisted.

Comments

Leave a comment