Chrome's Sixth Zero-Day of 2026 Is Being Exploited Right Now

Google rushed out a Chrome patch for a V8 engine bug attackers are already exploiting - CERT-In has flagged it too. Here's what to do right now.

Sep 7, 2026 - 07:09
4 min read
 0
Chrome's Sixth Zero-Day of 2026 Is Being Exploited Right Now

If you haven't restarted your Chrome browser in the last few days, do it before you read the rest of this article. Google has confirmed that attackers are actively using a newly discovered flaw to break into people's browsers, and simply visiting the wrong web page is enough to get hit.

What actually broke

The bug is tracked as CVE-2026-85046, and it lives inside V8 — the engine that runs all the JavaScript on every website you open in Chrome. The technical name for the flaw is a "type confusion" bug: the engine gets tricked into treating one kind of data as if it were a completely different kind, and a carefully crafted web page can use that mix-up to slip in its own code. Once that code runs, it's operating inside Chrome's "sandbox," the isolated box the browser normally keeps web page code locked inside so it can't touch the rest of your computer. This particular bug matters because it's part of a chain that researchers say can be used to escape that box.

Google rated it 8.8 out of 10 on the CVSS severity scale, and confirmed in its own release notes that a working exploit is already circulating. A researcher named Salvatore Gulizia gets credit for reporting it, and was paid a $1,000 bounty for the find — a modest sum for a bug serious enough to get an emergency patch.

Google is aware that an exploit for CVE-2026-85046 exists in the wild.

That single line, buried in Chrome's release notes, is the reason security teams around the world spent the first days of September pushing out updates instead of sitting on them.

The sixth one this year, and it's not just Chrome

This is the sixth zero-day — a flaw being exploited before a fix existed — that Google has had to patch in Chrome in 2026 alone, following earlier emergency fixes for CVE-2026-2441, CVE-2026-3909, CVE-2026-3910, and CVE-2026-5281, among others. The fixed version is Chrome 152.0.7977.82 (and .83 on Windows and macOS), and it's rolling out in stages rather than to everyone at once.

It also isn't only a Chrome problem. Microsoft Edge, Brave, Opera, and Vivaldi are all built on the same open-source Chromium engine, so they inherit the same V8 flaw and need the identical underlying fix once their teams ship it. If you use any Chromium-based browser, checking for an update isn't optional.

  • Open Chrome's menu, go to Help, then "About Google Chrome" — this forces a version check.
  • If an update is waiting, click "Relaunch" immediately — downloading it isn't enough, the browser has to restart to actually apply the fix.
  • Confirm the version reads 152.0.7977.82 or higher (.83 on Windows and macOS).
  • Do the same check on Edge, Brave, Opera, or Vivaldi if you use them instead of or alongside Chrome.

Why this one matters more for Indian users

Chrome's share of the browser market in India is well above the global average — most estimates put it near 90% on both desktop and mobile — which means a huge slice of the country's internet users were exposed while this sat unpatched. That scale is likely why CERT-In, India's Computer Emergency Response Team under MeitY, put out its own advisory flagging the flaw — the fourth Chrome-specific warning CERT-In has issued this year. CERT-In advisories don't carry the force of law for ordinary users the way a regulator's order might, but they're the government's official signal that a bug is serious enough for citizens to act on, and this one lines up with a matching deadline from CISA, the US government's own cybersecurity agency, which gave its federal agencies until September 18 to patch or disconnect vulnerable systems.

For India's fast-growing base of digital-first users — people banking, shopping, and working entirely through a browser tab — an unpatched V8 bug isn't an abstract IT problem. A single malicious ad or a compromised website is all it takes, no download, no click on a suspicious link required beyond just opening the page. If you'd rather not depend entirely on Chrome getting these patches out in time, we've previously covered some privacy-focused browser alternatives worth considering.

What this keeps confirming

Six zero-days patched in a single year, all requiring nothing more than loading a web page, says something uncomfortable about how much trust we place in a browser by default. Security researchers keep finding these bugs before criminals can fully weaponize them, which is the system working as intended — but it only works if people actually install the updates Google ships. The fix here took Google roughly a day from confirming exploitation to shipping a patch. Whether that patch actually protects you depends entirely on whether you clicked relaunch.

Short URL: https://code24.in/a67e9651

What's Your Reaction?

Like Like 0
Dislike Dislike 0
Love Love 0
Funny Funny 0
Angry Angry 0
Sad Sad 0
Wow Wow 0
Code24 Team Code24 Team