[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$f2Ti9Z4JWSLBLTJRKYv03PMzZecp-TnzeH-jaaA_9TSc":3},{"article":4,"iocs":50},{"id":5,"title":6,"slug":7,"summary":8,"ai_summary":9,"brief":10,"full_text":11,"url":12,"image_url":13,"published_at":14,"ingested_at":15,"relevance_score":16,"entities":17,"category_id":27,"category":28,"article_tags":32},"88fedab0-7681-4c11-930a-157024b41894","Google Patches 6th Chrome Zero-Day of 2026","google-patches-6th-chrome-zero-day-of-2026-995421","Google’s Chrome 152 security update resolves 12 vulnerabilities, including a high-severity type confusion flaw in the V8 engine. The post Google Patches 6th Chrome Zero-Day of 2026 appeared first on SecurityWeek.","Google has released Chrome 152 updates to address 12 vulnerabilities, including a high-severity type confusion zero-day in the V8 engine, tracked as CVE-2026-85046. This marks the sixth Chrome zero-day exploited in 2026, with Google acknowledging that an exploit exists in the wild. The update resolves several other high and medium-severity bugs.","Google patches 6th Chrome zero-day of 2026, a type confusion flaw in the V8 engine.","Google on Thursday rolled out fresh Chrome 152 security updates that resolve 12 vulnerabilities, including an exploited zero-day. Tracked as CVE-2026-85046, the high-severity bug is described as a type confusion issue in Chrome’s V8 JavaScript and WebAssembly engine. It was reported by Salvatore Gulizia, who received a $1,000 bug bounty reward. “Google is aware that an exploit for CVE-2026-85046 exists in the wild,” the internet giant’s advisory reads. While the company has not shared details on the security defect, type confusion flaws in the V8 engine may be exploited to perform remote read\u002Fwrite operations via crafted HTML pages. Type confusion vulnerabilities are memory corruption bugs that could lead to crashes, remote code execution, and other malicious behavior. CVE-2026-85046 is the sixth Chrome zero-day patched in 2026. The other five are CVE-2026-2441, CVE-2026-3909, CVE-2026-3910, CVE-2026-5281, and CVE-2026-11645.Advertisement. Scroll to continue reading. The security defect was resolved in Chrome versions 152.0.7977.82\u002F.83 for Windows and macOS, and version 152.0.7977.82 for Linux. The updates address nine other high-severity bugs, including out-of-bounds read\u002Fwrite, incomplete cleanup, use-after-free, race condition, improper resource exposure, and type confusion issues. Three of them have been reported by external researchers. Additionally, Google fixed two medium-severity improper input validation and use-after-free weaknesses. Related: Chrome and Firefox Updates Patch Dozens of Vulnerabilities Related: Chrome 152 Patches Over 300 Vulnerabilities Related: Over 3 Million WordPress Sites Affected by Migration Plugin Vulnerability Related: Cisco Warns of Unpatched Secure Email Flaws, Patches Critical Switch Vulnerabilities Written By Ionut Arghire Ionut Arghire is an international correspondent for SecurityWeek. Daily Briefing Newsletter Subscribe to the SecurityWeek Email Briefing for the latest cybersecurity threats, trends, and expert insights. More from Ionut Arghire Cisco Warns of Unpatched Secure Email Flaws, Patches Critical Switch VulnerabilitiesExploit Published for Fresh Cleo Harmony VulnerabilityMalicious Virtualizor Update Served via BGP HijackingChrome and Firefox Updates Patch Dozens of Vulnerabilities23-Year-Old Sality P2P Botnet DisruptedHackers Start Exploiting Critical Langflow VulnerabilityFive Venezuelans Plead Guilty in US Court to ATM JackpottingRansomware Gang Claims Nutex Health Data Breach Latest News Catch Raises $5 Million for AI Executive Assistant With GuardrailsVMware Workstation and Fusion Updates Patch Critical VulnerabilityManchester Airports Group Data on 8.8 Million People Leaked After Ransom RefusalCapsule Security Launches ‘AI Circuit Breaker’ to Stop Rogue AgentsHiddenLayer Raises $100 Million for AI Runtime SecurityAI Agent Firewall Startup AIR Security Emerges From Stealth With $50 Million153 Million Driver License Images Offered on Dark WebOver 3 Million WordPress Sites Affected by Migration Plugin Vulnerability Trending Daily Briefing NewsletterSubscribe to the SecurityWeek Email Briefing to stay informed on the latest threats, trends, and technology, along with insightful columns from industry experts. Virtual Event: Attack Surface Management Summit 2026 September 16, 2026 Join as speakers examine the various components of ASM strategy, the push to mandate continuous asset visibility and inventory tools, and the use of red-teaming, bug bounties and pen-tests in modern security programs. Register Webinar: Minimum Viable Business: Can You Prove Your Organization Would Recover? September 2, 2026 In this live webinar, learn how to define your minimum viable business, identify the systems it depends on, measure actual recovery time against business requirements, and present the gaps to the board as measurable risk. Register People on the MoveTom Bonos has been named Chief Revenue Officer at Sumo Logic.Axonius has appointed Chris Jones as CTSO and Dan Schoenbaum as SVP of Business Development.Optiv has appointed Sean Forkan as Chief Revenue Officer (CRO).More People On The MoveExpert Insights What the Hugging Face Incident Teaches Security Leaders About AI Agent Access Security teams must treat autonomous agents as highly privileged identities. (Etay Maor) The Future of AI-Driven Security Depends on Complete Data For twenty-five years, \"data\" in security meant logs and events. But logs are a lossy representation of reality. (Danelle Au) The MFA Identity Trap: When Authentication Creates a False Sense of Security Organizations must distinguish identity verification, authentication and threat detection, or risk successfully authenticating the attackers they are trying to stop. (Torsten George) Silent Patches Don’t Stop Attackers – They Blind Defenders Silent patches can become exploit intelligence for attackers while leaving defenders without the context needed to prioritize risk. (Tod Beardsley) Hired for One Job, Judged on Another: The CISO’s Real Problem The skills that get a CISO hired are rarely the skills they are judged on later. Most security leaders are stuck in that gap. Closing it is the real job. (Sravish Sridhar) Flipboard Reddit Whatsapp Whatsapp Email","https:\u002F\u002Fwww.securityweek.com\u002Fgoogle-patches-6th-chrome-zero-day-of-2026\u002F","https:\u002F\u002Fwww.securityweek.com\u002Fwp-content\u002Fuploads\u002F2024\u002F06\u002FChrome.jpeg","2026-09-04T11:31:52+00:00","2026-09-04T12:00:08.533657+00:00",8,[18,21,24],{"name":19,"type":20},"Chrome 152","product",{"name":22,"type":23},"V8 JavaScript and WebAssembly engine","technology",{"name":25,"type":26},"Google","vendor","80544778-fabb-4dcd-aa35-17492e5dcf4f",{"id":27,"icon":29,"name":30,"slug":31},null,"Vulnerabilities","vulnerabilities",[33,38,43,45],{"category":34},{"id":35,"icon":29,"name":36,"slug":37},"02371804-cf6d-4449-98de-f1a2d4d9b266","Tools","tools",{"category":39},{"id":40,"icon":29,"name":41,"slug":42},"574f766a-fb3f-487c-8d2c-0720ae75471b","Zero-day","zero-day",{"category":44},{"id":27,"icon":29,"name":30,"slug":31},{"category":46},{"id":47,"icon":29,"name":48,"slug":49},"e7b231c8-5f79-4465-8d38-1ef13aea5a14","Threat Intelligence","threat-intelligence",[51,55,58,60,62,64],{"type":52,"value":53,"context":54},"cve","CVE-2026-85046","High-severity type confusion vulnerability in Chrome's V8 engine.",{"type":52,"value":56,"context":57},"CVE-2026-2441","Previously patched Chrome zero-day in 2026.",{"type":52,"value":59,"context":57},"CVE-2026-3909",{"type":52,"value":61,"context":57},"CVE-2026-3910",{"type":52,"value":63,"context":57},"CVE-2026-5281",{"type":52,"value":65,"context":57},"CVE-2026-11645"]