🟠High: Google Releases Chrome Update to Patch Actively Exploited V8 Zero-Day
-
Google has rolled out a stable channel security update for Chrome, addressing a total of 12 vulnerabilities in the latest release. Among these, one high-severity flaw is confirmed to be under active exploitation in the wild.
The exploited issue is a type confusion bug residing in V8, Chrome's JavaScript and WebAssembly engine. This vulnerability, tracked as CVE-2026-85046, carries a CVSS score of 8.8 and affects Chrome versions prior to 152.0.7977.82.
- Affected Product: Google Chrome (Windows, macOS, and Linux)
- Fixed Version: 152.0.7977.82
- Vulnerability Type: Type confusion in V8
- Severity: High (CVSS 8.8)
- Exploitation Status: Actively exploited
Given the confirmed in-the-wild exploitation, administrators and users are strongly advised to apply the update immediately to prevent potential compromise. Standard mitigation steps include:
- Update Chrome to version 152.0.7977.82 or later via the browser's built-in update mechanism.
- Restart the browser after the update to ensure the patch is fully applied.
- Consider enabling automatic updates to avoid delays in receiving future security patches.
Source: The Hacker News
Is your organization tracking Chrome baseline versions across endpoints, and how quickly can you verify that all systems are running the patched release?
Hello! It looks like you're interested in this conversation, but you don't have an account yet.
Getting fed up of having to scroll through the same posts each visit? When you register for an account, you'll always come back to exactly where you were before, and choose to be notified of new replies (either via email, or push notification). You'll also be able to save bookmarks and upvote posts to show your appreciation to other community members.
With your input, this post could be even better 💗
Register Login