Chrome CVE-2026-85046: Zero-Day Fix and How to Update
By Nihar Ranjan Das · Thu Oct 08 2026 · 7 min read · 1 views
View as a Web StorySecurity#chrome#browser security#security#zero-day#CVE#V8

Chrome CVE-2026-85046 zero-day exploit fix
If your Chrome is older than version 152.0.7977.82, a web page can run attacker code inside your browser. Google confirmed that an exploit for CVE-2026-85046 exists in the wild, which makes this the sixth Chrome zero-day patched in 2026. The fix is a normal browser update, and checking it takes about 30 seconds. This guide shows how to check, how to force the update, what to do on Edge, Brave, and other Chromium browsers, and what IT teams should do when users never restart.
The short answer: am I safe?
You are safe from this bug if Chrome reports 152.0.7977.82 or higher. Open chrome://version and read the first line. Anything lower is vulnerable.
| Platform | Vulnerable | Fixed version |
|---|---|---|
| Windows | Before 152.0.7977.82 | 152.0.7977.82 or .83 |
| macOS | Before 152.0.7977.82 | 152.0.7977.82 or .83 |
| Linux | Before 152.0.7977.82 | 152.0.7977.82 |
Google's update rolls out gradually "over the coming days and weeks", so your copy may not have it yet even if the release is out. Do not wait for it to arrive on its own. Force the check yourself.
How to force the Chrome update right now
- Open the three-dot menu, then Help, then About Google Chrome.
- Chrome starts downloading the update immediately.
- Click Relaunch when the button appears.
- Return to
chrome://versionand confirm the number.
The relaunch is the step people skip. Chrome downloads the patch in the background, but the old, vulnerable code keeps running until the browser restarts. If the Relaunch button has been sitting in the top-right corner for days, you are not patched. Chrome restores your tabs after relaunching, so you lose nothing.
On Linux, update through your package manager instead. On Debian or Ubuntu that is sudo apt update && sudo apt install --only-upgrade google-chrome-stable. Then restart the browser.
If About Chrome says "up to date" but the version is old, a managed policy may be pinning updates. Check chrome://policy for TargetVersionPrefix or update-related settings, and ask your IT team.
What CVE-2026-85046 actually is
CVE-2026-85046 is a type confusion bug (CWE-843) in V8, the engine that runs JavaScript and WebAssembly in Chrome. It scores 8.8 (High) on CVSS.
Type confusion means the engine treats a piece of memory as one type when it is really another. Here, the researcher described a compiler bug in which an array holding PACKED_ELEMENTS is assigned the PACKED_SMI_ELEMENTS map. That mismatch affects both of V8's optimizing compilers, Maglev and TurboFan, and it can be turned into arbitrary read and write access on the JavaScript heap.
In practice, an attacker needs you to open a crafted web page. No download or click on a prompt is required beyond loading the page. The attacker's code then runs inside Chrome's sandbox. The sandbox is a real barrier, and a full takeover of your computer normally needs a second exploit to escape it. That is why these bugs are often chained with a separate sandbox-escape flaw in real attacks.
Who found it and when
Independent researcher Salvatore Gulizia, known as Serotav, reported the bug on August 4, 2026. Google paid a $1,000 bounty. Google patched it roughly a month later, in the Stable release published in early September, and the public disclosure followed on September 4, 2026.
Advertisement
Google has kept the bug-tracker entry restricted, which is standard practice while most users are still unpatched. Google's only statement on exploitation is that it is "aware that an exploit for CVE-2026-85046 exists in the wild". It has not said who is being targeted or how.
Edge, Brave, Opera, Vivaldi, and other Chromium browsers
These browsers share Chrome's V8 engine, so they carry the same vulnerable code until their vendors ship their own build. Each vendor publishes its own version number, so do not compare it with Chrome's 152.0.7977.82.
- Microsoft Edge: Menu, then Help and feedback, then About Microsoft Edge. Check Microsoft's Edge security release notes for the fixed build.
- Brave: Menu, then About Brave.
- Opera and Vivaldi: Open the About page from the main menu and let it update.
- Electron apps (Slack, Discord, VS Code, and similar): They bundle their own Chromium. These ship fixes on the app's own release schedule, and the lag can be weeks. Update them from inside the app.
The practical rule is to update every Chromium-based browser you use, then restart each one.
Is Chrome safe to keep using until I update?
For a short window, yes, if you change your habits. Until you are patched:
- Avoid unfamiliar sites and links from email, chat, and ads.
- Keep Safe Browsing on (Settings, Privacy and security, Security).
- Do not use an old tab as your "main" session. Close and relaunch.
- Consider using Chrome's Enhanced protection mode, which checks sites in real time.
None of this replaces patching. The exploit works from a web page, so the only complete fix is the update.
For IT teams: how to verify and enforce the patch
A bug that is exploited in the wild turns patch speed into a risk metric. These steps close the gap.
1. Find who is behind. In Chrome Browser Cloud Management, open Reports and filter by Chrome version. In Intune, Jamf, or Workspace ONE, run the installed-app inventory and flag anything below 152.0.7977.82.
2. Force relaunches. Set the RelaunchNotification policy to 2 (required) and RelaunchNotificationPeriod to a short value, for example 86,400,000 milliseconds (24 hours). Users then get a countdown, and Chrome restarts itself when it expires. This is the single most effective setting, because the number-one reason fleets stay vulnerable is browsers that never restart.
3. Check update policies. If UpdateDefault is disabled or TargetVersionPrefix pins an older build, the fleet cannot patch. Fix these before blaming users.
4. Cover the non-obvious copies. Portable Chrome, Chrome for Testing in CI, kiosk devices, and virtual desktop images all miss normal updates. Rebuild golden images with the fixed version.
5. Track the catalog. Check whether CISA has added the CVE to its Known Exploited Vulnerabilities catalog, and use any deadline there as your internal due date. This article could not confirm a specific CISA date, so look it up directly instead of relying on a number you read elsewhere.
6. Document exceptions. Where an app needs an older Chrome, isolate it with a separate profile or network segment, restrict it to internal sites, and set a removal date.
What if I cannot update today?
Use compensating controls, and treat them as a bridge of days, not weeks.
- Restrict browsing to a list of trusted sites for high-risk users.
- Turn on Safe Browsing and enhanced protection.
- Use DNS or web filtering to block newly registered domains and known malicious categories.
- Disable JavaScript for untrusted sites with the
DefaultJavaScriptSettingpolicy and an allowlist. This breaks many sites, so use it only for narrow, high-risk groups. - Watch for unusual browser child processes and crashes. Exploit attempts often crash the renderer before they work.
Why does Chrome keep having zero-days?
Google has fixed six actively exploited Chrome zero-days in 2026: CVE-2026-2441, CVE-2026-3909, CVE-2026-3910, CVE-2026-5281, CVE-2026-11645, and now CVE-2026-85046. Several of them sit in V8 or related graphics code.
Three reasons explain the pattern. Chrome has more than three billion users, so one working exploit has enormous value. V8 compiles JavaScript into machine code on the fly, and optimizing compilers like TurboFan and Maglev make assumptions about types. A wrong assumption becomes a memory bug. And finding these flaws pays: exploit brokers pay far more than a $1,000 bounty for a working Chrome chain, so the bounty alone does not capture the bug's market value.
The takeaway for ordinary users is simple. Browser updates are now a security control, not a nuisance, and a restart is part of the patch.
How to make sure this never catches you out again
- Restart Chrome at least once a week. Pinned tabs and "continue where you left off" make this painless.
- Turn on automatic updates for every Chromium-based app you use.
- Remove browser extensions you do not use. Each one adds attack surface and permissions.
- Use a separate browser profile for sensitive accounts such as banking and admin consoles.
- Subscribe to the Chrome Releases blog or a security feed so you hear about the next one on day one.
Sources
Advertisement
FAQ
What is CVE-2026-85046?
It is a type confusion vulnerability in Chrome's V8 JavaScript engine with a CVSS score of 8.8. It lets a remote attacker run code inside Chrome's sandbox through a crafted HTML page. Google says an exploit exists in the wild.
Which Chrome version fixes CVE-2026-85046?
Chrome 152.0.7977.82 or .83 on Windows and macOS, and 152.0.7977.82 on Linux. Anything older is vulnerable.
Do I need to restart Chrome after updating?
Yes. The download happens in the background, but the vulnerable code stays in memory until you click Relaunch. Your tabs come back after the restart.
Does the bug affect Edge, Brave, and Opera?
They share the V8 engine, so they need their own updates. Open each browser's About page and install the latest release. Check the vendor's notes for the fixed build number.
Can this bug take over my whole computer?
On its own it runs code inside Chrome's sandbox. Taking over the machine usually needs a second exploit that escapes the sandbox. Do not rely on that, because attackers do chain bugs.
How do I know if I was attacked?
There is no simple indicator. Look for unexpected browser crashes, new extensions, or unfamiliar logins on your accounts. If you handle sensitive data, change key passwords and review account activity after patching.
Comments
Loading…
Sign in to join the conversation.