Skip to content
LIVE

Google Confirms Active Attacks Exploiting a Chrome Flaw. Patch Now, Then Check Every Chromium Browser You Use

CVE-2026-85046 is a type-confusion bug in Chrome's V8 engine that only requires visiting a malicious page. Federal agencies have until September 18 to patch — everyone else should not wait that long.

Meridians Money Desk

Published 6 September 2026 · Updated 6 September 2026 · 3 min read

Google Confirms Active Attacks Exploiting a Chrome Flaw. Patch Now, Then Check Every Chromium Browser You UseSoftware
Photo: Photo by cottonbro studio / Pexels (Pexels License — free to use, no attribution legally required (credited above as good practice).)

The short answer

  • Google confirmed on September 4, 2026 that an exploit for CVE-2026-85046, a high-severity flaw in Chrome's V8 JavaScript engine, exists in the wild.
  • The fix ships in Chrome 152.0.7977.82 or later on Windows and Linux, and 152.0.7977.82 or .83 on macOS.
  • The bug carries a CVSS score of 8.8 and can be triggered simply by visiting a malicious webpage — no download or click required beyond loading the page.
  • CISA has given federal civilian agencies until September 18, 2026 to patch; the same fix applies to every Chromium-based browser, including Edge, Brave, Opera and Vivaldi.

Google says attackers are already using a newly patched Chrome vulnerability, and the fix takes about a minute to apply.

On September 4, 2026, Google confirmed that an exploit for CVE-2026-85046 exists in the wild — meaning the flaw was being used against real users before the patch was available. The bug is a type-confusion flaw in V8, Chrome's JavaScript engine, that can let an attacker corrupt memory and potentially run their own code inside Chrome's renderer process. It carries a CVSS severity score of 8.8 out of 10, and requires nothing more than visiting a malicious webpage to trigger.

Which version fixes it

  • Windows and Linux: Chrome 152.0.7977.82 or later
  • macOS: Chrome 152.0.7977.82 or 152.0.7977.83

How to check and update

  1. Open Chrome's menu, go to Settings, then About Chrome.
  2. Chrome checks for updates automatically when this page opens; let it finish.
  3. Confirm the version number reads 152.0.7977.82 or higher.
  4. Restart the browser — the update does not fully apply until you do.

It's not just Chrome

Microsoft Edge, Brave, Opera and Vivaldi are all built on the Chromium engine that contains the same V8 component, so each needs its own update, on its own timeline, from its own vendor. Check each one separately rather than assuming a Chrome update covers them.

The federal deadline

The Cybersecurity and Infrastructure Security Agency has given federal civilian agencies until September 18, 2026 — a 14-day window — to apply the patch under its Known Exploited Vulnerabilities catalog rules. That deadline is a floor for government systems, not a signal that everyone else has two weeks to spare: this is already being exploited, so home and business users should update immediately rather than waiting.

Sources

Every factual claim above is traceable to these documents. Check them — that is why they are here.

About this byline

Meridians Money Desk is an editorial desk at Meridians, not an individual. A desk byline means the article was produced and fact-checked to that desk's published standards. Read our editorial standards and corrections policy.

Sponsored

Paid placement · not editorial

Related reading

The Meridians Brief

One considered email a week

What changed, what it costs you, and what to do about it — from the Meridians desks. No sponsored picks disguised as recommendations.

Sign-up opens with our launch issue. Nothing is sent or stored yet.