Google released Chrome 152 security updates on September 3, 2026, patching 12 vulnerabilities including a high-severity flaw that attackers are already exploiting, according to Google’s own advisory and reporting from The Hacker News, SecurityWeek and BleepingComputer.
A Type Confusion Bug in Chrome’s Core Engine
The exploited flaw, tracked as CVE-2026-85046 and rated CVSS 8.8, is a type confusion vulnerability in V8, the JavaScript and WebAssembly engine that powers Chrome. Google’s advisory describes the bug as allowing a remote attacker to execute arbitrary code inside Chrome’s sandbox via a specially crafted HTML page. Google said it is aware that an exploit for the flaw exists in the wild but withheld technical details of the observed attacks to limit further exploitation while users update. Security researcher Salvatore Gulizia, credited with reporting the issue on August 4, 2026, received a $1,000 bug bounty for the disclosure.
Sixth Exploited Chrome Zero-Day This Year
CVE-2026-85046 is the sixth actively exploited Chrome zero-day Google has patched in 2026, following CVE-2026-2441, CVE-2026-3909, CVE-2026-3910, CVE-2026-5281 and CVE-2026-11645. The same update, which brings Chrome to version 152.0.7977.82/.83 on Windows and macOS and 152.0.7977.82 on Linux, also fixes nine other high-severity issues spanning Crash Reporting, Network, Compositing, WebGL, CacheStorage, DevTools and Skia components.
Why It Matters for Security Operators
Chromium-based browsers sit behind a large share of enterprise workstations, control-room terminals and web-based video management and access-control clients, making browser zero-days a recurring entry point into otherwise segmented environments. Google is rolling out the fix gradually; users and IT administrators are advised to confirm they are running version 152.0.7977.82 or later via Chrome’s Settings > About Chrome menu and restart the browser to complete the update rather than waiting for automatic rollout.

Leave a Reply