Google Chrome 152 Patches Exploited V8 Flaw and 11 Others

Google’s Chrome 152 security release fixes 12 vulnerabilities, including an actively exploited type-confusion flaw in the V8 engine.
Google Chrome 152 Patches Exploited V8 Flaw and 11 Others
Share

Google has released version 152 of its Chrome browser, a security update that fixes 12 vulnerabilities, including CVE-2026-85046, an actively exploited flaw in its V8 engine. The cited flaw affects installations earlier than 152.0.7977.82, so users on older builds should update promptly.

CVE-2026-85046 carries a CVSS severity score of 8.8 and is classified as a type-confusion vulnerability in V8, the component that executes JavaScript and WebAssembly code. The patch release was covered, as first reported by SecurityWeek.

The V8 issue is the sixth reported Chrome zero-day of 2026

SecurityWeek described the vulnerability as Google’s sixth Chrome zero-day of 2026. A zero-day is disclosed or exploited before a complete fix becomes broadly available, which means defenders may have faced risk before version 152 arrived. The known exploitation makes this patch more pressing than a routine maintenance release.

The stakes extend beyond a single website or script. V8 handles the JavaScript and WebAssembly code that the browser runs, so a security weakness in that engine can affect core web-content processing. Google’s release also corrects 11 additional vulnerabilities, giving users a broader reason to move to the current build.

Older browser builds remain exposed to the cited flaw

Google set 152.0.7977.82 as the version threshold for the V8 weakness. That gives IT teams a clear marker for identifying potentially exposed endpoints, especially where browser updates are managed on a schedule rather than installed immediately. Individual users should confirm that their installed browser has received the 152 release.

Google has not identified the attackers or campaigns that used CVE-2026-85046, and the available material does not explain the exploitation method. The summaries also do not list the full range of affected browser versions or identify the other 11 vulnerabilities addressed in this release. Those gaps limit how precisely organizations can assess exposure beyond the version threshold provided for the V8 issue.

This article was produced with AI assistance from multi-source reporting and is published under our editorial standards.

Apple Foldable iPhone Output Stays Low Before September Debut

Apple Foldable iPhone Output Stays Low Before September Debut

Prev
Seattle Times, Newsday Sue OpenAI, Microsoft Over AI Training

Seattle Times, Newsday Sue OpenAI, Microsoft Over AI Training

Next