Google Issues Urgent Chrome Update To Block Active Attacks

Google has released a new security update for its Chrome browser after confirming that attackers are actively exploiting a high-severity vulnerability in the browser’s V8 JavaScript and WebAssembly engine.

The latest update addresses 12 security vulnerabilities, including the zero-day flaw identified as CVE-2026-85046, which carries a CVSS severity score of 8.8, putting it in the high-severity category.

The vulnerability, described as a type-confusion flaw in V8, could allow a remote attacker to execute arbitrary code within Chrome’s sandbox by luring a victim to a specially crafted HTML page.

Google’s advisory confirmed that an exploit for the vulnerability exists in the wild, although the company has withheld technical details of the attacks to reduce the risk of further exploitation while users install the security update.

The flaw was discovered by security researcher Salvatore Gulizia, also known as Serotav, who reported it to Google on August 4, 2026. Google awarded him a $1,000 bug bounty for the responsible disclosure.

Google’s latest security bulletin lists several other high-severity weaknesses affecting Chrome’s crash reporting, networking, compositing, V8, WebGL, CacheStorage, DevTools and Skia components. Two additional vulnerabilities were rated medium severity.

The security update moves Chrome to version 152.0.7977.82/.83 for Windows and macOS, while Linux users are being moved to 152.0.7977.82. Google said the update would roll out progressively over the coming days and weeks.

The development is significant because CVE-2026-85046 represents the sixth actively exploited Chrome zero-day addressed by Google since the beginning of 2026, according to security researchers. Previous exploited flaws include CVE-2026-2441, CVE-2026-3909, CVE-2026-3910, CVE-2026-5281 and CVE-2026-11645.

The latest emergency patch also comes against the backdrop of an unusually high volume of security fixes across Chrome this year. An earlier Chrome 152 update addressed more than 300 vulnerabilities, including 10 rated critical and 61 rated high severity. Of the 327 weaknesses addressed in that update, 299 were discovered internally by Google.

Meanwhile, Google had patched more than 2,000 Chrome vulnerabilities during 2026 as of late August, underscoring the scale of the security challenge facing one of the world’s most widely used web browsers.

The increasing use of artificial intelligence in vulnerability discovery is also changing the pace at which browser security flaws are identified. Google has increasingly relied on automated security tools and AI-assisted techniques to discover vulnerabilities before they are weaponised, while external researchers continue to identify high-value flaws through bug bounty programmes.

For Nigerian users, the development carries particular significance as Chrome is widely used for online banking, e-commerce, government services, social media and other digital transactions. A compromised browser can potentially expose users to risks ranging from malicious code execution to theft of sensitive information, depending on how vulnerabilities are chained with other weaknesses.

Google has urged users to update Chrome immediately. On desktop devices, users can check for the latest version by going to More > Help > About Google Chrome, allowing the browser to download the update and then selecting Relaunch.

Consequently, users of other Chromium-based browsers, including Microsoft Edge, Brave, Opera and Vivaldi, have also been advised to apply corresponding security updates as they become available, because Chromium-based browsers can share underlying components affected by vulnerabilities discovered in Chrome.


We’ve got the edge. Get real-time reports, breaking scoops, and exclusive angles delivered straight to your phone. Don’t settle for stale news. Join THISTIMES on WhatsApp for 24/7 updates →


Join Our WhatsApp Channel