AIZANOI NEWS

Monday, 7 September 2026

Technology

Chrome 152 patches sixth 2026 zero-day, an actively exploited V8 type confusion bug also affecting other Chromium browsers

Google on 4 September shipped Chrome 152.0.7977.82/.83 to fix CVE-2026-85046, a high-severity type confusion in the V8 JavaScript and WebAssembly engine that has been exploited in the wild, according to Google's release notes and a SecurityWeek advisory. The bug, which chained Maglev JIT compiler optimisation handling of Array.prototype.sort with Array.prototype.fill map migration, is the sixth Chrome zero-day of 2026 and the third to target V8 this year. CISA added it to its Known Exploited Vulnerabilities catalogue and set a federal patching deadline of 25 September.

By Aizanoi News Desk · Edited by Aizanoi Editorial Desk ·

ChromeV8zero dayCVE-2026-85046CISAbrowser security

Sources

SecurityWeekThe Hacker News