Google Patches Actively Exploited Chrome Zero-Day Ahead of Strict EU Cyber Resilience Rules
The tech giant resolved a high-severity V8 engine flaw, marking Chrome's sixth zero-day exploit of the year, just days before European 24-hour incident reporting requirements take effect.

Google released a critical security update for its Chrome web browser on Sept. 3, remediating 12 software vulnerabilities including a zero-day flaw being actively exploited in real-world cyberattacks. The actively exploited bug, designated as CVE-2026-85046, represents the sixth zero-day vulnerability discovered in Chrome so far this year. The majority of the security issues resolved in the maintenance release were classified as high-severity flaws affecting the browser's core codebase.
The zero-day vulnerability stems from a type confusion error within V8, the open-source JavaScript and WebAssembly engine that powers Chrome. Assigned a Common Vulnerability Scoring System (CVSS) rating of 8.8 out of 10, the flaw allows remote attackers to execute arbitrary code inside the browser sandbox by directing unsuspecting targets to a specially crafted web page. According to reporting by TechRadar cited in the release, threat actors were actively leveraging the security hole prior to the patch deployment.
Google addressed the flaw by deploying updated Chrome builds 152.0.7977.82 and 152.0.7977.83. Following its established security protocol, the search giant restricted public access to granular technical details regarding the vulnerability until a significant majority of its user base updates to the patched builds. Because the V8 engine is central to the Chromium open-source project, competing browsers that rely on the framework—including Microsoft Edge, Brave, Opera, and Vivaldi—are also exposed and must distribute downstream updates via phased rollouts.
Independent security researcher Salvatore Gulizia originally disclosed the bug to Google on Aug. 4, receiving a $1,000 payout through Chrome's Vulnerability Reward Program. While Google's bug bounty program advertises maximum rewards reaching up to $250,000 for critical findings, the company did not publicly detail why this report received $1,000. Bounty awards generally depend on the quality and completeness of the disclosure as well as whether another researcher previously submitted a duplicate report, though Google maintains a policy of withholding internal evaluation metrics for specific payouts.
The security update arrives at a significant regulatory moment for global technology firms selling software products into European markets. As a product containing digital elements, Chrome falls under the legal purview of the European Union's Cyber Resilience Act (CRA), whose mandatory vulnerability disclosure directives begin applying on Sept. 11—just eight days after Google issued the Chrome patch.
Under the incoming Cyber Resilience Act requirements, software manufacturers will be legally required to report actively exploited vulnerabilities and major security breaches to European regulators. The statutory framework mandates an initial early warning submission within 24 hours of confirming active exploitation. That initial advisory must be followed by a comprehensive incident notification within 72 hours, alongside a final technical report due within 14 days of making a software patch or corrective measure available.
Regulatory filings will be funneled through a single European submission portal, delivering advisories simultaneously to relevant national computer security incident response teams and the European Union Agency for Cybersecurity (ENISA). ENISA will subsequently broadcast the vulnerability details to government authorities in every EU member state where the product is marketed. First reported by The Next Web, the 24-hour reporting mandate is expected to fundamentally reshape vulnerability response workflows and pressure global software supply chains.
Crucially, the 24-hour reporting clock under European law is triggered by a manufacturer becoming aware of active exploitation, rather than the initial receipt of a bug report. Because Google publicly confirmed in its release notes on Sept. 3 that an exploit existed in the wild, the company satisfied its existing reporting standards prior to the law taking effect. However, starting next week, identical security disclosures will require mandatory filings for Google, which recently signed a corporate joint letter advocating that digital defense be prioritized at the executive leadership level.
Sources
Written by
The Company Wire
Inside the companies building what’s next. Reporting on startups, technology, funding and the people shaping them.



