Google has confirmed that the Chrome browser, prior to version 152.0.7977.82/.83, is vulnerable to a zero-day flaw that has already been exploited, allowing a remote attacker to execute arbitrary code within the browser security sandbox via a maliciously crafted web page.

Google Chrome’s Srinivas Sista said, in a September 3 advisory , that the high-severity-rated CVE-2026-85046 vulnerability, reported by an external bug hunter called Salvatore Gulizia, involved a “type confusion in V8.” The V8 in question being Chrome’s JavaScript and WebAssembly engine, developed by Google itself and essentially the engine under the hood of the world’s most used web browser. A type confusion vulnerability, meanwhile, is yet another memory flaw , which Chrome has seen more than its fair share of recently ( 1 , 2 , 3 .) In this case, it occurs when software loses track of the correct memory slot types and, in effect, can be tricked into processing data that it shouldn’t.

The good news is that the exploited zero-day is patched, along with 11 other security vulnerabilities, making the Chrome browser safe to use, with the latest update that takes it to versions 152.0.7977.82/.83 for Windows and Mac, 152.0.7977.82 for Linux and 152.0.7977.82 for Android. The latter should see the latest Chrome app update “become available on Google Play over the next few days,” according to Sista.

Automatic updates will also roll out to users on other platforms “over the coming days/weeks” Sista said. Given the nature of this vulnerability, especially the fact that an active exploit has been confirmed by Google, one would hope that the patch will reach users sooner rather than later. If you are asked to restart your browser, this is a giveaway that it has. If not, you can use the three-dot Chrome menu to manually start the update search, download and installation process.