Google patches Chrome V8 flaw already exploited in the wild
Chrome Stable 152.0.7977.82/.83 for Windows and Mac, and 152.0.7977.82 for Linux, patches CVE-2026-85046, a High V8 type confusion Google says is already exploited in the wild. Salvatore Gulizia (Serotav) reported it on 4 August 2026. Chrome Releases lists a $1,000 reward. The update has 12 security fixes. Google named no targets or actors.

Google pushed a Chrome Stable security update on Thursday, 3 September 2026, and said it is already seeing an exploit for one of the bugs. The Chrome Releases notes update Stable to 152.0.7977.82/.83 on Windows and Mac and 152.0.7977.82 on Linux, rolling out over the coming days and weeks.
This is a Stable channel security update plus Google's own in-the-wild acknowledgment. It is not a named campaign, and Google did not publish a public exploit.
The bug Google flagged is CVE-2026-85046, a High severity type confusion in V8. Google's own line is: "Google is aware that an exploit for CVE-2026-85046 exists in the wild." The notes do not name targets, actors, or exploit details. A typical V8 type-confusion risk is that a crafted page can start an exploit attempt, which is the known shape, not a disclosed ransomware run or a confirmed enterprise campaign.
The extra detail in the notes, past the 0-day headline, is the patched builds and the report trail. Salvatore Gulizia (Serotav) reported the V8 bug on 4 August 2026. Chrome Releases lists a $1,000 reward against that CVE. The same update ships 12 security fixes in total.
Patching a confirmed in-the-wild browser bug is a different job from chasing a researcher claim, such as the CrowdStrike FalconFlank privilege-escalation claim or an Exchange proof of concept. It sits with other patch-now, already-exploited cases this week, including the JFrog Artifactory auth bypass and the WordPress All-in-One WP Migration takeover.
Force Chrome, Chromium, and Edge enterprise fleets onto 152.0.7977.82 or later this week, confirm auto-update rings actually deliver that build, and block older Stable channels until inventory shows it.
Cyberpresso: daily cyber & AI brief
Free daily newsletter, read in 5 minutes.
Subscribe free