hacker-news · Crawled Sep 4, 2026
Google Releases Chrome Update to Patch Actively Exploited V8 Zero-Day
Read original article ↗AI Summary
Google has released a security update for Chrome to address CVE-2026-85046, a high-severity type confusion vulnerability in the V8 JavaScript and WebAssembly engine that is actively exploited in the wild. The flaw allows a remote attacker to execute arbitrary code within the sandbox by using a crafted HTML page. Security researcher Salvatore Gulizia discovered and reported the vulnerability, which stems from incorrect handling of JavaScript array maps leading to arbitrary read/write capabilities on the JavaScript heap. Users are urged to update to Chrome version 152.0.7977.82 or later to mitigate the risk.
AI-extracted · verify before operational use
No entities or IoCs were extracted from this article.