Summary
Google shipped an emergency Chrome update on September 3, 2026, patching a high-severity zero-day vulnerability, CVE-2026-85046, that was already being exploited in the wild. The flaw is a type confusion bug in V8, Chrome's JavaScript and WebAssembly engine, and marks the sixth actively exploited Chrome zero-day Google has patched so far this year. It allows a remote attacker to execute arbitrary code inside Chrome's sandbox through a specially crafted HTML page. Security researcher Salvatore Gulizia reported the bug on August 4, 2026, and received a $1,000 bug bounty. Google withheld technical and proof-of-concept details, standard practice while the fix rolls out. The patched version is Chrome 152.0.7977.82/.83 for Windows and macOS and 152.0.7977.82 for Linux. Because the flaw lives in the open-source Chromium engine, other Chromium-based browsers — Edge, Brave, Opera, Vivaldi — inherit it and require their own updates.
Timeline
| Date | Event |
|---|---|
| Aug 4, 2026 | Salvatore Gulizia reports CVE-2026-85046 to Google, receives $1,000 bounty |
| Sept 3, 2026 | Google patches CVE-2026-85046 in Chrome 152.0.7977.82/.83, confirms exploit exists in the wild |
| Sept 5, 2026 | Sixth actively exploited Chrome zero-day patched in 2026 |
Domain Intelligence
google.com — 72.67
Score sits above the 70-point trust threshold, carrying a routine canonical-signal marker only. This score does not reflect the Chrome vulnerability described above — it is a separate, broader signal about the domain. See TTO-2026-0905-105, "When 87 Doesn't Mean Safe," for more on why a high score and an active incident can coexist.
The Trust Observatory · thetrustobservatory.com · September 4, 2026