ConicPlex

Start Your Project

A cracked glass sphere in Chrome browser colors glowing on a developer desk beside a laptop and monitors, symbolizing an actively exploited Chrome zero-day

On this Page

Google Patches an Actively Exploited Chrome Zero-Day in V8 (CVE-2026-85046)

Google patched CVE-2026-85046, an actively exploited Chrome zero-day in V8, on September 3, 2026. Here is what it affects and what to check.

Sameer Malek

September 5, 2026

Google shipped a Chrome update on September 3, 2026 to patch CVE-2026-85046, a type confusion bug in the V8 JavaScript engine that Google confirms is already being exploited in the wild. The fix ships in Chrome 152.0.7977.82/.83 for Windows and Mac and 152.0.7977.82 for Linux, rolling out gradually over the coming days. A remote attacker only needs a victim to open a crafted webpage to trigger it, no download or click required beyond the page load itself. This is the sixth Chrome zero-day Google has patched in 2026.

What CVE-2026-85046 actually does

V8 is the engine that runs every script on every page you load in Chrome. The bug sits in how V8’s two compiler tiers, maglev and turbofan, handle arrays: under the right conditions, an array holding packed elements can end up tagged with the wrong internal type. That confusion gives an attacker arbitrary read and write access inside the JavaScript heap, which is enough to run attacker-controlled code within Chrome’s sandboxed renderer process.

Security researcher Salvatore Gulizia, who goes by Serotav, reported the flaw on August 4 and was paid a $1,000 bounty. Third-party writeups from BleepingComputer and The Hacker News put the CVSS score at 8.8. Google hasn’t disclosed whether the attacks it’s tracking pair this bug with a separate sandbox-escape flaw, which is the usual second step for a full device compromise, only that an exploit already exists and is being used.

Who should act, and how

Chrome updates itself in the background on most machines, but the fix only applies after a restart. Open the menu, go to Help, then About Google Chrome, and it will finish updating and prompt you to relaunch if it hasn’t already. For most people that’s the whole fix.

A few setups need a manual look instead of assuming it’s handled:

  • Managed or kiosk devices where IT policy pins Chrome to a specific build.
  • Electron apps and embedded WebViews bundling their own Chromium runtime rather than the system browser.
  • CI pipelines or scraping infrastructure running headless Chrome pinned to an older version number.

None of this requires touching your own site’s code. It’s a browser-side patch, but given Google is already seeing it exploited, it’s worth confirming the update actually landed rather than trusting it happened automatically, especially on any machine used to manage a client’s WordPress or hosting dashboard. That kind of routine check across a team’s machines is exactly what falls through the cracks without a standing Website Development Care Plan watching for it.

This is the second Chrome patch we’ve flagged in under two weeks. Chrome 152’s original release on August 25 fixed a critical ANGLE flaw; this update stays within the same 152 branch but addresses a bug already being used in real attacks, which makes it more urgent than a routine patch cycle.

Sources

Sameer Malek is a Senior Full Stack Developer at ConicPlex, working across the stack on projects that don’t fit neatly into one platform or framework. He’s often the person weighing a genuine platform or architecture decision rather than defending one side of it, since his work regularly crosses between WordPress, custom builds, and everything in between. He writes here about the comparisons and tradeoffs that come up when there’s more than one reasonable way to build something.

Leave a Reply

Your email address will not be published. Required fields are marked *

Keep reading

Plugins

A split living room showing a worn, dated half next to a bright, renovated half, illustrating a before and after transformation

Best Before and After Image Slider Plugins for the WordPress Block Editor

Five before and after image slider plugins for the WordPress block editor compared, with real install counts, ratings, and setup…

Sajil Memon

September 4, 2026

Plugins

Desk with a laptop glowing WooCommerce purple next to shipping boxes and packing tape, symbolizing hiding a WooCommerce shipping method

Best Plugins to Hide a WooCommerce Shipping Method by Product Category

Hiding a WooCommerce shipping method for specific product categories, rather than for the whole cart, is a narrower problem than…

Husen Memon

September 4, 2026

Plugins

Desk with a laptop glowing warm orange, an hourglass, and an analog clock, symbolizing a WordPress sale-page countdown timer

How to Add a Countdown Timer to a WordPress Sale Page (5 Plugins Compared)

A countdown timer on a WordPress sale page works because it turns “buy eventually” into “buy now.” If the offer…

Sajil Memon

September 4, 2026

WhatsApp
Husen Memon
Husen Memon
Typically replies instant