Google Warns of New Chrome Zero-Day Vulnerability Exploited in Cyber Attacks

www.news4hackers.com-google-warns-of-new-chrome-zero-day-vulnerability-exploited-in-cyber-attacks-google-warns-of-new-chrome-zero-day-vulnerability-exploited-in-cyber-attacks

Google has released an updated version of the Chrome browser to resolve a critical zero-day vulnerability in the V8 engine, alongside 11 additional security flaws.

Overview of the Vulnerability

The flaw, designated CVE-2026-85046, is categorized as a type confusion vulnerability. It was reported by researcher Salvatore Gulizia, who is recognized online under the handle Serotav. The latest update elevates Chrome to version 152.0.7977.82/.83 on Windows and macOS, and 152.0.7977.82 on Linux, as part of a phased deployment.

Active Exploitation and Technical Details

The company confirmed that exploitation of CVE-2026-85046 is currently active in the wild. However, specific technical details about the flaw were not disclosed to prevent adversaries from leveraging the information before users can apply the patch.

Type Confusion Vulnerability Explained

Type confusion vulnerabilities occur when software incorrectly interprets data types, leading to potential memory corruption. The V8 engine, which is responsible for executing JavaScript and WebAssembly code in Chrome, could be compromised through a maliciously crafted HTML page containing harmful JavaScript. This could enable remote code execution within the browser’s sandboxed renderer process.

Additional Security Fixes

In addition to the zero-day, the update resolves nine other high-severity issues. These include use-after-free and out-of-bounds memory flaws in components such as Crash Reporting, Network, Compositing, WebGL, CacheStorage, DevTools, and Skia. A race condition in the V8 engine was also addressed.

Historical Context of Active Exploits

CVE-2026-85046 marks the sixth actively exploited vulnerability fixed in Chrome this year. Earlier resolved issues include:

  • An out-of-bounds read and write flaw in the V8 engine (CVE-2026-11645), patched in June after being exploited.
  • An iterator invalidation vulnerability (CVE-2026-2441) in CSSFontFeatureValuesMap, fixed in February.
  • Two zero-day flaws exploited in March attacks: an out-of-bounds write in the Skia graphics library (CVE-2026-3909) and a flawed implementation in the V8 engine (CVE-2026-3910).
  • A use-after-free vulnerability in Dawn (CVE-2026-5281), a WebGPU implementation, resolved in April.

Recommendations for Users

Users are required to restart the browser after the update to ensure all patches are applied. The update process is part of a broader effort to mitigate risks associated with actively exploited vulnerabilities.

Broader Implications for Software Security

The advisory highlights the ongoing challenges of securing complex software ecosystems, particularly those involving widely used browsers. Organizations are encouraged to prioritize timely application of updates to minimize exposure to emerging threats.

“The update process is part of a broader effort to mitigate risks associated with actively exploited vulnerabilities.”



About Author

en_USEnglish