Google patched CVE-2026-85046, a high-severity type confusion bug in Chrome's V8 engine that was already being exploited in the wild. Restart Chrome now (version 152.0.7977.82 or later) instead of waiting for the update to apply itself.

Read the full story: Chrome V8 Zero-Day CVE-2026-85046 Is Under Attack: Patch Now →

Transcript

Google just patched a Chrome bug that attackers were already using before the fix existed. It's called a type confusion vulnerability, and here's what that actually means. V8, Chrome's JavaScript engine, makes fast assumptions about what kind of data it's looking at. Trick it into misreading one type of object as another, and you get a foothold to manipulate memory the page should never touch. CVSS score, 8.8. CISA already added it to the Known Exploited Vulnerabilities list with a September 16th deadline for federal agencies. Here's the part most people miss. Chrome auto-downloads the fix in the background, but it doesn't apply until you actually restart the browser. If you've had the same tabs open for days, you're still running the vulnerable version. This is the sixth Chrome zero-day this year. Close the browser. Reopen it. That's the whole fix.