TTO-2026-0905-102 · September 4, 2026 Active Exploitation

Google Patches Sixth Actively-Exploited Chrome Zero-Day of 2026

google.comCVE-2026-85046 CVSS 8.8Type confusion in V8Sixth exploited Chrome 0-day of 2026Patched Sept 3

Summary

Google shipped an emergency Chrome update on September 3, 2026, patching a high-severity zero-day vulnerability, CVE-2026-85046, that was already being exploited in the wild. The flaw is a type confusion bug in V8, Chrome's JavaScript and WebAssembly engine, and marks the sixth actively exploited Chrome zero-day Google has patched so far this year. It allows a remote attacker to execute arbitrary code inside Chrome's sandbox through a specially crafted HTML page. Security researcher Salvatore Gulizia reported the bug on August 4, 2026, and received a $1,000 bug bounty. Google withheld technical and proof-of-concept details, standard practice while the fix rolls out. The patched version is Chrome 152.0.7977.82/.83 for Windows and macOS and 152.0.7977.82 for Linux. Because the flaw lives in the open-source Chromium engine, other Chromium-based browsers — Edge, Brave, Opera, Vivaldi — inherit it and require their own updates.

Timeline

DateEvent
Aug 4, 2026Salvatore Gulizia reports CVE-2026-85046 to Google, receives $1,000 bounty
Sept 3, 2026Google patches CVE-2026-85046 in Chrome 152.0.7977.82/.83, confirms exploit exists in the wild
Sept 5, 2026Sixth actively exploited Chrome zero-day patched in 2026

Domain Intelligence

google.com — 72.67

Score sits above the 70-point trust threshold, carrying a routine canonical-signal marker only. This score does not reflect the Chrome vulnerability described above — it is a separate, broader signal about the domain. See TTO-2026-0905-105, "When 87 Doesn't Mean Safe," for more on why a high score and an active incident can coexist.

Domain intelligence available at warmbadge.com.
The Trust Observatory · thetrustobservatory.com · September 4, 2026