Updated
Updated · Malwarebytes Labs · Sep 5
Google Patches 26 Chrome Flaws, Including 1 Exploited V8 Bug and 2 Critical RCE Risks
Updated
Updated · Malwarebytes Labs · Sep 5

Google Patches 26 Chrome Flaws, Including 1 Exploited V8 Bug and 2 Critical RCE Risks

3 articles · Updated · Malwarebytes Labs · Sep 5

Summary

  • Chrome 152.0.7977.82/.83 for Windows and Mac, and .82 for Linux, fixes an actively exploited V8 flaw plus 26 security issues in the desktop browser.
  • CVE-2026-85046 is a high-severity V8 bug already exploited in the wild; Google said a crafted HTML page could execute arbitrary code inside Chrome’s sandbox, and HKCERT rated the overall risk extremely high.
  • Two other critical use-after-free bugs—CVE-2026-84353 in Shared Tab Groups and CVE-2026-84352 in WebGL—could let attackers run code outside the sandbox if users are lured to malicious HTML content.
  • The update is rolling out automatically, but users can trigger it through Settings > About Chrome and must restart the browser to complete protection.
  • The V8 issue is the sixth actively exploited Chrome zero-day patched this year, and other Chromium-based browsers may also need corresponding fixes.

Insights

If Chrome's sandbox isolates threats, how are attackers consistently weaponizing V8 memory flaws to bypass these defenses entirely?
Why did a critical Chrome zero-day already exploited by hackers yield only a $1,000 reward for the researcher who reported it?
With Google withholding the attackers' identities, who is actively exploiting this critical browser vulnerability in the wild right now?