Skip to content
Breaking:

Google Releases Emergency Chrome Security Update to Patch Exploited Zero-Day Bug

The patch resolves 12 security vulnerabilities, including a high-severity V8 engine flaw being actively targeted in real-world attacks.

By The Company Wire3 min read
Share
Google — Google Releases Emergency Chrome Security Update to Patch Exploited Zero-Day Bug
Google — Google Releases Emergency Chrome Security Update to Patch Exploited Zero-Day Bug. Photo: TechRadar Pro.

Google has issued an emergency software update for its Chrome web browser across Windows, macOS, and Linux platforms to address 12 security vulnerabilities, including a high-severity flaw currently being targeted in active security exploits.

According to security disclosures published on September 3 and first reported by TechRadar Pro, the updated browser builds are designated as version 152.0.7977.82/.83 for Windows and Mac systems, while Linux systems are receiving version 152.0.7977.82. Google indicated that the patch deployment will proceed on a gradual rollout schedule for end users.

The emergency update resolves a total of 12 distinct software defects, with 10 of the reported vulnerabilities rated as high severity. Among the resolved security issues is a type confusion flaw located in V8, the open-source JavaScript execution engine that enables Chrome to run web applications and dynamic site functionality.

Tracked under the identifier CVE-2026-85046, the zero-day flaw was discovered and reported to the company by security researcher Salvatore Gulizia. Google awarded Gulizia a $1,000 bug bounty for identifying the issue prior to its broader public disclosure.

Entry records in the National Vulnerability Database describe CVE-2026-85046 as a type confusion bug within Google Chrome's V8 component that permits a remote adversary to execute arbitrary code inside the browser sandbox environment using a specially crafted HTML web page.

Google has restricted specific details regarding the vulnerability's attack vectors, following its standard policy of withholding granular technical information until a majority of the Chrome user base receives the software patch. Detailed technical analysis regarding the bug has been made available on Gulizia's personal blog.

The patch represents the sixth zero-day vulnerability resolved by Google within the Chrome browser codebase since the beginning of the year. Because the underlying software components are shared across the open-source Chromium platform, the vulnerability also poses potential risks to alternative web browsers built on the same architecture.

Third-party Chromium-based web browsers, including Microsoft Edge, Brave, Opera, and Vivaldi, also require security updates to remediate the vulnerability. Users across affected desktop platforms are advised to check their browser configuration settings to verify that the latest security patches have been fully applied.

Sources

  1. TechRadar Pro

Company: Google

Written by

The Company Wire

Newsroom · San Francisco

Inside the companies building what’s next. Reporting on startups, technology, funding and the people shaping them.