<?xml version="1.0" encoding="UTF-8"?><rss xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:atom="http://www.w3.org/2005/Atom" version="2.0"><channel><title><![CDATA[🟠 High: Google Releases Chrome Update to Patch Actively Exploited V8 Zero-Day]]></title><description><![CDATA[<p dir="auto">Google has rolled out a stable channel security update for Chrome, addressing a total of <strong>12 vulnerabilities</strong> in the latest release. Among these, one high-severity flaw is confirmed to be under active exploitation in the wild.</p>
<p dir="auto">The exploited issue is a <strong>type confusion bug</strong> residing in <strong>V8</strong>, Chrome's JavaScript and WebAssembly engine. This vulnerability, tracked as <strong><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-85046" target="_blank" rel="noopener noreferrer nofollow ugc">CVE-2026-85046</a></strong>, carries a CVSS score of <strong>8.8</strong> and affects Chrome versions prior to <strong>152.0.7977.82</strong>.</p>
<ul>
<li><strong>Affected Product:</strong> Google Chrome (Windows, macOS, and Linux)</li>
<li><strong>Fixed Version:</strong> 152.0.7977.82</li>
<li><strong>Vulnerability Type:</strong> Type confusion in V8</li>
<li><strong>Severity:</strong> High (CVSS 8.8)</li>
<li><strong>Exploitation Status:</strong> Actively exploited</li>
</ul>
<p dir="auto">Given the confirmed in-the-wild exploitation, administrators and users are strongly advised to apply the update immediately to prevent potential compromise. Standard mitigation steps include:</p>
<ul>
<li>Update Chrome to version <strong>152.0.7977.82</strong> or later via the browser's built-in update mechanism.</li>
<li>Restart the browser after the update to ensure the patch is fully applied.</li>
<li>Consider enabling automatic updates to avoid delays in receiving future security patches.</li>
</ul>
<p dir="auto">Source: <a href="https://thehackernews.com/2026/09/google-releases-chrome-update-to-patch.html" target="_blank" rel="noopener noreferrer nofollow ugc">The Hacker News</a></p>
<p dir="auto">Is your organization tracking Chrome baseline versions across endpoints, and how quickly can you verify that all systems are running the patched release?</p>
]]></description><link>https://xploitlk.com/topic/221/high-google-releases-chrome-update-to-patch-actively-exploited-v8-zero-day</link><generator>RSS for Node</generator><lastBuildDate>Sat, 05 Sep 2026 12:37:46 GMT</lastBuildDate><atom:link href="https://xploitlk.com/topic/221.rss" rel="self" type="application/rss+xml"/><pubDate>Sat, 05 Sep 2026 04:30:24 GMT</pubDate><ttl>60</ttl></channel></rss>