Skip to main content
VTechFusion Technologies
Google Patches Actively Exploited Chrome Zero-Day, CISA Sets September 18 Deadline
InsightsNewsIndustry & AI News
Industry & AI News4 min readSeptember 4, 2026

Google Patches Actively Exploited Chrome Zero-Day, CISA Sets September 18 Deadline

VT

VTechFusion Team

VTechFusion Technologies

Google shipped Chrome 152.0.7977.82/.83 on September 4, 2026 to patch CVE-2026-85046, a high-severity type confusion flaw in Chrome's V8 JavaScript engine that Google confirms is being actively exploited in the wild.

What the Vulnerability Allows

CVE-2026-85046 carries a CVSS score of 8.8. Type confusion in V8's JIT compiler — which occurs when the compiler makes incorrect assumptions about an object's type during optimization passes — allows a remote attacker to achieve arbitrary JavaScript heap read/write and execute code inside Chrome's sandboxed renderer via nothing more than a crafted HTML page.

The Sixth Actively Exploited Chrome Zero-Day of 2026

Google is aware that a working exploit for CVE-2026-85046 exists in the wild, making this the sixth actively exploited Chrome zero-day patched so far in 2026 — a specific, sobering count that underscores how frequently browser engines remain a live target for real-world attackers.

CISA Sets a Hard Deadline

  • CISA added CVE-2026-85046 to its Known Exploited Vulnerabilities catalog on September 4, 2026
  • Federal civilian executive branch agencies face a remediation deadline of September 18, 2026
  • The fix shipped in Chrome 152.0.7977.82/.83 for Windows and macOS, and 152.0.7977.82 for Linux

Every Chromium-Based Browser Is Affected

Edge, Brave, Opera and Vivaldi all inherit the same V8 flaw through their shared Chromium foundation and require the identical 152.0.7977.82 build to be patched — organizations standardized on any Chromium-based browser, not just Chrome itself, need to confirm the update has been applied.

Responsibly Disclosed, Quickly Fixed

The vulnerability was reported by researcher Salvatore Gulizia (aka Serotav) on August 4, 2026, who earned a $1,000 bug bounty for the disclosure — a one-month window from private report to public patch that reflects a reasonably fast turnaround given the flaw was already being exploited by the time Google shipped the fix.

Filed under:Industry & AI News
All News

Frequently Asked Questions

What is CVE-2026-85046?

A high-severity (CVSS 8.8) type confusion vulnerability in Chrome's V8 JavaScript engine that allows a remote attacker to execute arbitrary code inside Chrome's sandbox via a crafted HTML page. Google patched it in Chrome 152.0.7977.82/.83 on September 4, 2026, and confirmed it is being actively exploited.

What is the CISA deadline for this vulnerability?

CISA added CVE-2026-85046 to its Known Exploited Vulnerabilities catalog on September 4, 2026, with a remediation deadline of September 18, 2026 for federal civilian executive branch agencies.

Which browsers besides Chrome are affected?

Edge, Brave, Opera and Vivaldi all inherit the same flaw through their shared Chromium foundation and require the identical 152.0.7977.82 build to be patched.

Media & Press Enquiries

For editorial enquiries, expert commentary, or case study access.

Start Today

Ready to Build Something Great?

Let's turn your idea into a product. Book a free 30-minute discovery call with our team — no commitment, just clarity.