Google warns of new Chrome zero-day flaw exploited in attacks
Google updates Chrome to fix a high-severity zero-day flaw in V8 engine and 11 other vulnerabilities.
Intelligence analysis by Qwen 2.5 (3B)

Google has patched a new Chrome zero-day flaw, CVE-2026-85046, which was exploited in the wild.
Google fixed a bug in Chrome that could let bad guys run their own code. It's like a security update to keep your computer safe from hackers.
Analysis
{"#type confusion flaw":"CVE-2026-85046 is a type confusion flaw in the V8 engine, which can lead to memory corruption and remote code execution. The flaw was reported by Salvatore Gulizia, known as Serotav.","V8 engine details":"V8 is the open-source JavaScript and WebAssembly engine used by Chrome. The update addresses nine other high-severity vulnerabilities, including use-after-free and out-of-bounds memory flaws.","Timeline of Chrome fixes":"Google has fixed six active zero-days since the start of the year, including CVE-2026-11645 and CVE-2026-2441."}
Key points
- Google patched a new Chrome zero-day flaw
- The flaw is a type confusion in the V8 engine
- The update addresses nine other high-severity vulnerabilities
The update will help protect Chrome users from potential attacks.
If attackers find a way to exploit this flaw, it could lead to serious security issues.



