Google Patches 6th Chrome Zero-Day of 2026
Google has released Chrome 152 to address six zero-day vulnerabilities, including a critical type confusion issue in the V8 JavaScript engine. This is the sixth zero-day for Chrome in 2026, highlighting an ongoing effort to patch security flaws within the browser. Users are strongly advised to update immediately to mitigate potential exploitation.
Google released Chrome 152 on Thursday, containing updates to resolve 12 security vulnerabilities, including a high-severity type confusion issue. This vulnerability, tracked as CVE-2026-85046, stems from a flaw within Chrome’s V8 JavaScript and WebAssembly engine. Salvatore Gulizia reported the issue, earning a $1,000 bug bounty. Google’s advisory indicates that an exploit for CVE-2026-85046 is already active in the wild.
Type confusion vulnerabilities are a specific type of memory corruption bug that can lead to crashes, remote code execution, and other malicious behavior. Google has addressed this issue in Chrome versions 152.0.7977.82/.83 for Windows and macOS, and version 152.0.7977.82 for Linux.
Beyond CVE-2026-85046, the update also addresses nine other high-severity bugs, including out-of-bounds read/write, incomplete cleanup, use-after-free, race condition, improper resource exposure, and type confusion issues. Three of these were reported by external researchers. Additionally, Google fixed two medium-severity improper input validation and use-after-free weaknesses.
Google has been actively patching vulnerabilities in Chrome throughout 2026, with this being the sixth zero-day discovered and addressed. The company continues to prioritize security and provide timely updates to protect users from potential threats.