Site icon TechloMedia

Google Chrome gets emergency security update for exploited zero-day

Chrome logo

Photo: Google

Google has released a new Chrome security update that fixes a zero-day vulnerability already being exploited in the wild. The flaw affects the browser’s V8 JavaScript and WebAssembly engine and could potentially allow attackers to execute malicious code.

The vulnerability is tracked as CVE-2026-85046 and has been rated high severity. Google has confirmed that an exploit for the vulnerability exists in real-world attacks.

Chrome users should update their browsers as soon as possible, especially because Google has not yet shared detailed information about the attacks. Google has kept details private to give users more time to install the patch before attackers can use the technical information to develop more reliable exploits.

CVE-2026-85046 is a type confusion vulnerability in V8, the engine Chrome uses to process JavaScript and WebAssembly content. This bug can cause software to treat data as the wrong type. In a browser engine, this can create serious memory safety problems and potentially allow an attacker to manipulate the browser’s memory.

An attacker could potentially exploit the flaw through specially crafted web content. This means a malicious website could be enough to trigger an attack. Similar attack chains can also be delivered through phishing links, compromised websites, or malicious advertisements.

The vulnerability was reported by security researcher Salvatore Gulizia, also known as Serotav, on August 4, 2026. Google awarded a $1,000 bounty for the report.

The update also fixes vulnerabilities in components such as WebGL, Network, DevTools, Skia, CacheStorage, and Compositing.

You can manually check for the update in Chrome.

Open Chrome > three-dot menu > Help > About Google Chrome.

Chrome will check for the latest version and download it if an update is available. You should restart the browser after the installation is complete.

Exit mobile version