Cybersecurity

Chrome Just Patched Its Sixth Zero-Day of the Year. Yes, You Should Relaunch It Now

0

Google has pushed out a Chrome security update fixing a dozen vulnerabilities, and one of them is already being used in real attacks. Tracked as CVE-2026-85046, the flaw is a type-confusion bug in V8, the engine that runs JavaScript and WebAssembly inside Chrome, and Google has confirmed that an exploit for it exists in the wild. The practical upshot for the rest of us is simple: update your browser, and do it now rather than later.

What makes this class of bug dangerous is how little the victim has to do. A type-confusion flaw in V8 can be turned into the ability to read and write memory the browser should never allow, which an attacker can escalate into running their own code. The delivery mechanism is just a web page. Land on a booby-trapped site, and the exploit can fire without any further click, which is exactly why browser zero-days are prized by attackers and spyware vendors alike.

A familiar pattern

If this feels like déjà vu, that is because it is. This is the sixth actively exploited Chrome zero-day Google has patched since the start of the year, and V8 keeps turning up as the culprit. The browser is the single most exposed piece of software on most people’s computers, constantly rendering untrusted code from every site you visit, so it is a permanent front line. Google, per its usual practice, is not saying who is exploiting the bug or how widely, a deliberate silence meant to give users time to update before more attackers pile on.

There is a small, slightly awkward footnote. The researcher who found and responsibly reported the flaw, Salvatore Gulizia, received a bug bounty of just $1,000, a modest reward for a vulnerability serious enough to end up exploited in the wild and added to the US government’s must-patch list. It is a reminder of how much value defenders get from researchers relative to what those researchers are typically paid.

What to do

The good news, unlike some recent security scares, is that a fix already exists, and applying it is trivial. Chrome should update itself, but the change only takes effect when you relaunch, and plenty of people leave the browser running for weeks. So open the menu, go to Help, then About Google Chrome, let it pull the update, and click relaunch. On Windows and macOS you want version 152.0.7977.82 or later. Anyone using a Chromium-based browser like Edge, Brave, Opera, or Vivaldi should apply their equivalent update as soon as it lands.

CISA has already added the flaw to its catalogue of known exploited vulnerabilities and given federal agencies until September 18 to patch, which is the government’s way of confirming this is a genuine threat, not a theoretical one. For everyone else, there is no deadline and no committee, just a browser quietly asking to be relaunched. So when did you last restart Chrome? If you cannot remember, that is your answer, and it takes about thirty seconds to fix.

A Magento Zero-Day Is Backdooring Online Stores Right Now, and There’s No Patch

Previous article

Pixxel Just Raised India’s Biggest Space Round. It Already Has Satellites in Orbit to Show for It.

Next article

You may also like

Comments

Comments are closed.