Google Chrome Zero-day Vulnerability Exploited in the Wild (CVE-2026-85046)

Google released security updates to address 12 vulnerabilities impacting the Chrome browser. One of these vulnerabilities, tracked as CVE-2026-85046, is being exploited in the wild. CVE-2026-85046 is a type confusion vulnerability in the V8 JavaScript engine.

CISA acknowledged the active exploitation of the vulnerability by adding it to its Known Exploited Vulnerabilities Catalog. CISA urges users to patch the vulnerability before September 18, 2026. 

CVE-2026-85046 is the sixth zero-day vulnerability patched by Google since the start of the year. The list includes:

  1. CVE-2026-2441 
  2. CVE-2026-3909 
  3. CVE-2026-3910 
  4. CVE-2026-5281 
  5. CVE-2026-11645

Google addressed 11 other vulnerabilities with the zero-day. The list includes:

  • CVE-2026-85052: This is an out-of-bounds read flaw in CrashReporting.
  • CVE-2026-85043: This is an incomplete cleanup flaw in Network.
  • CVE-2026-85048: This is a use-after-free flaw in Compositing.
  • CVE-2026-85045: This is a race condition flaw in the V8 JavaScript engine.
  • CVE-2026-85050: This is an out-of-bounds write flaw in WebGL.
  • CVE-2026-85053: This is an improper resource exposure flaw in CacheStorage.
  • CVE-2026-85042: This is a use-after-free flaw in DevTools.
  • CVE-2026-85049: This is a use-after-free flaw in Skia.
  • CVE-2026-85051: This is a type confusion flaw in Compositing.
  • CVE-2026-85047: This is an improper input validation flaw in Transactions Platform.
  • CVE-2026-85044: This is a use of released resources flaw in Mobile.

Affected Versions

The vulnerability affects Google Chrome versions before 152.0.7977.82/.83.

Mitigation

Customers must upgrade to the stable channel version 152.0.7977.82/.83 for Windows and Mac and 152.0.7977.82 for Linux, which will roll out over the coming days/weeks.

For more information, please refer to the Google Chrome Release Page.

Qualys Detection

Qualys customers can scan their devices with QID 388637 to detect vulnerable assets.

Rapid Response with TruRisk™ Eliminate

Qualys TruRisk Eliminate and its Zero-Touch Patching feature provide a seamless, automated process for patching vulnerabilities like this.

Zero-Touch Patching identifies the most vulnerable products in your environment and automates the deployment of necessary patches and configuration adjustments. This streamlines the patching process and ensures vulnerabilities are addressed promptly.

Please continue to follow Qualys Threat Protection for more coverage of the latest vulnerabilities.

References
https://chromereleases.googleblog.com/2026/09/stable-channel-update-for-desktop_01882797386.html