[CRITICAL] "Google patches actively exploited Chrome zero-day (CVE-2026-85046)"
criticalDetails
A high-severity type confusion vulnerability in the V8 JavaScript engine allows a remote attacker to execute arbitrary code. The vulnerability is a zero-day, meaning it was exploited before a patch was available. Google has confirmed that an exploit for this CVE exists in the wild.
Affected Systems
Google Chrome versions prior to 152.0.7977.82 for Linux and 152.0.7977.82/.83 for Windows and macOS.
Potential Impact
Successful exploitation could lead to arbitrary code execution on user workstations, enabling attackers to compromise user data, install malware, or pivot to other systems on the network.
Mitigations
Update all Chrome instances to the latest version immediately. Per CISA KEV requirements, patching must be completed by 2026-09-18.