Google patches multiple Chrome bugs including a V8 flaw being used in attacks
Google patched 12 Chrome vulnerabilities on 3 September including CVE-2026-85046, a type confusion bug in V8 already being exploited, the sixth such flaw this year. Eight days later the Cyber Resilience Act starts requiring manufacturers to report actively exploited vulnerabilities within 24 hours of becoming aware.
Google patched 12 vulnerabilities in Chrome on 3 September, most of them high severity. One was already being used in attacks, TechRadar reported.
The bug is CVE-2026-85046, a type confusion flaw in V8, Chrome’s JavaScript engine. It carries a CVSS score of 8.8 and lets a remote attacker run code inside the sandbox through a crafted web page.
The fixed builds are 152.0.7977.82 and .83. Google’s release notes say an exploit exists in the wild, and the company withheld the details until most browsers are patched.
It is the sixth actively exploited Chrome zero-day this year. Every Chromium browser inherits the flaw, so...
Copyright of this story solely belongs to thenextweb.com. To see the full text click HERE