Chrome's sixth zero-day of the year is already being used
Google put out a Chrome update on 4 September carrying the one sentence in a release note that always means the same thing: "Google is aware that an exploit for CVE-2026-85046 exists in the wild." The fixed builds are 152.0.7977.82/.83 on Windows and macOS, 152.0.7977.82 on Linux. Anything older is a browser somebody already knows how to get into.
The flaw sits in V8, the piece of Chrome that runs JavaScript on every page you open. It's a type confusion bug rated 8.8: the compiler hands an array the wrong internal type, and from there an attacker gets read and write access to Chrome's memory and can run code inside the browser's sandbox. In practice a booby-trapped page is the entire attack. Nothing downloaded, no fake installer, no password typed anywhere.
Two details stand out. Salvatore Gulizia reported it on 4 August and was paid a $1,000 bounty, a startlingly small price for a bug that turns any web page into code execution. And this is the sixth actively exploited Chrome zero-day of 2026, following CVE-2026-2441, CVE-2026-3909 and 3910, CVE-2026-5281 and CVE-2026-11645. Six in eight months is the pattern now rather than a bad year.
Chrome fetches the fix by itself but won't apply it until the browser restarts, and plenty of people never restart. Three-dot menu, Help, About Google Chrome, then read the number and let it relaunch. Edge, Brave, Opera and Vivaldi are built on the same engine and will need their own updates within days. Tendvane's app-update check runs through winget and lists which installed programs are sitting on old versions, browsers included, which beats opening each one to look.