Security

Chrome has an active zero-day: why this update can't wait

Google confirms CVE-2026-85046, in Chrome's V8 engine, is already being exploited. It's the browser's sixth zero-day of 2026, and the fix is already available.

Published on September 6, 2026 · The mitza.es team

On September 4, 2026, Google shipped an emergency Chrome update fixing a security flaw that's already being actively exploited. Google has confirmed it explicitly: a working exploit for CVE-2026-85046 is currently circulating, though the company withheld full technical attack details to give users time to update before it spreads further.

What CVE-2026-85046 actually is

The flaw is a type confusion bug in V8, Chrome's JavaScript and WebAssembly engine, rated CVSS 8.8. In practical terms: an array containing "packed" elements gets tagged with an incorrect internal type, which lets an attacker read and write arbitrary memory inside the browser. All it takes is for the victim to visit a malicious webpage — no file download or execution required.

Not an isolated incident: Chrome's sixth zero-day of 2026

This is now the sixth zero-day Google has patched in Chrome during 2026, a number that says a lot about the constant pressure browsers face as an attack surface. The same emergency update fixed 12 vulnerabilities in total, including two other critical flaws rated CVSS 9.6: one in DevTools (CVE-2026-85042) and another in the Skia graphics library (CVE-2026-85049), both also use-after-free bugs.

Which version you need and how to check

  • Windows and macOS: version 152.0.7977.82 or 152.0.7977.83.
  • Linux: version 152.0.7977.82.
  • To check your version: Chrome menu (the three dots) → Help → About Google Chrome. If an update is pending, it installs itself — you just need to restart the browser for it to take effect.

The severity is underscored by the fact that the US cybersecurity agency CISA added CVE-2026-85046 to its Known Exploited Vulnerabilities catalog the same day, requiring US federal agencies to patch by September 18, 2026. That specific mandate doesn't apply to Spanish businesses, but it's a clear signal of how seriously this vulnerability is being treated internationally.

Why this affects any SME, not just IT departments

Unlike other vulnerabilities we've covered — like the one in WordPress or Elementor Pro — which affect whoever manages a website, this one affects anyone who opens a browser on a company computer. Chrome is the most widely used browser in Spain and worldwide, so your exposure doesn't depend on which tech stack your business runs — it depends on whether your team's browsers are actually updated. A single employee running an outdated Chrome is the way in, and with an active exploit circulating, you don't need to be a specific target to be affected.

How we see it at Mitza

Chrome updates itself automatically in most cases, but "updates itself" isn't the same as "is updated": if the browser hasn't been restarted in days or weeks, the update sits downloaded but unapplied. That's exactly the kind of detail that slips through without active IT maintenance. Our IT maintenance service includes checking software versions across every device in your company, and if you want a one-off diagnostic of where your IT fleet stands right now, our audit covers that too.

Do you know what browser version your team is running?

We check software versions and apply pending critical updates across your company's computers.

No spam. No sales calls. Just your personalised reply.