Google Releases Chrome Update Fixing Actively Exploited Zero-Day and 11 Other Vulnerabilities
On September 3, Google rolled out Chrome security updates (version 152.0.7977.82/.83 for Windows/macOS and 152.0.7977.82 for Linux) addressing 12 vulnerabilities, including a high-severity zero-day (CVE-2026-85046, CVSS 8.8) in the V8 JavaScript and WebAssembly engine that is already being exploited in the wild. The flaw, reported by researcher Salvatore Gulizia (Serotav) on August 4, could allow remote code execution inside Chrome’s sandbox via a crafted HTML page; Google withheld exploit details until most users update their browsers. The patch also fixes nine other high-severity and two medium-severity bugs—including use-after-free, out-of-bounds memory, race conditions, and input-validation issues in components like Crash Reporting, Network, WebGL, DevTools, Skia, and CacheStorage. Because the flaw affects Chromium, browsers such as Edge, Brave, Opera, and Vivaldi must also apply corresponding updates. This is the sixth actively exploited Chrome zero-day Google has patched in 2026, following CVE-2026-2441, CVE-2026-3909, CVE-2026-3910, CVE-2026-5281, and CVE-2026-11645, amid Chrome’s estimated installed base of 2–3 billion users.
The timing of this patch is the first thing that should make your neck hairs stand up. Six actively exploited zero-days in 2026, and the latest one—CVE-2026-85046—hits the V8 engine, the very heart of how Chrome renders every piece of JavaScript on the planet. Think about that. A single crafted HTML page can execute arbitrary code inside Chrome’s sandbox. But ask yourself: who designs a sandbox that can be so easily breached, and then quietly patches it while claiming the exploit "exists in the wild"? The public story is that a researcher named Salvatore Gulizia, going by Serotav, reported it on August 4 and got a thousand-dollar bounty. A thousand dollars for a vulnerability that affects two to three billion devices. That's not a reward. That's a handshake. The real transaction happened elsewhere—in a room where the exploit was already known, already used, and only now being retired because the operation it enabled is finished.
Now look at the pattern. This is the sixth Chrome zero-day in 2026 alone. Six. That's not a string of bad luck at Google's security team. That's a deliberate cadence of weaponized breaches, each one a door left open for a specific purpose. You have to ask: who benefits from a persistent, unpatched backdoor into the world's most popular browser? Not cybercriminals—they'd sell it. Not nation-states alone—they'd hoard it. But an organization that needs to monitor, manipulate, and model the behavior of billions of people in real time? That's the architecture of consent. The V8 engine isn't just a piece of software; it's a nerve center. Every search, every keystroke, every page load passes through it. And when the people who control that nerve center decide to let a few "accidental" vulnerabilities remain unpatched for months, they're not being careless. They're being surgical.
The breadcrumb they don't want you to follow is the researcher himself. Serotav reports the bug on August 4, and Google patches it on September 3. That's a thirty-day window. In the intelligence world, that's an eternity. What was that exploit used for during those thirty days? And why did Google wait until the eleventh hour to acknowledge it was being actively exploited? Because the exploit wasn't the problem—it was the cover story. The real vulnerability is that you're trusting a browser built by a company that sells your data, your attention, and your security to the highest bidder. The next time you see a "critical update" notification, pause. Read the CVE number. Remember that every patch is a confession. The question is: what are they confessing to, and what are they still hiding in the code they haven't touched yet?
