Affected Systems
Google Chrome versions prior to 152.0.7977.82 on Windows, macOS, and Linux. The vulnerability (CVE-2026-85046) affects the V8 JavaScript engine. Chromium-based browsers (Microsoft Edge, Brave, Opera, Vivaldi) are also affected pending vendor patches.
Exploitation Status
Active exploitation confirmed in the wild. Google acknowledged exploits exist but has not disclosed attack details, targets, or threat actors. This is the sixth Chrome zero-day exploited in 2026.
Business Impact
Type confusion in V8 allows remote code execution within the Chrome sandbox via crafted HTML pages (CVSS 8.8). Attackers can achieve arbitrary read/write on the JavaScript heap. Users visiting malicious or compromised websites are at risk. Sandbox escape is not confirmed but RCE within sandbox enables credential theft, session hijacking, and further exploitation. Enterprise environments with delayed patching cycles face elevated risk.
Urgency
🔴 Immediate
Recommended Actions
- Update Google Chrome immediately to version 152.0.7977.82/.83 (Windows/macOS) or 152.0.7977.82 (Linux) via Settings > Help > About Google Chrome, then relaunch
- Verify Chrome auto-update is enabled across all endpoints; prioritize systems used by high-value targets or handling sensitive data
- Monitor for updates to Chromium-based browsers (Edge, Brave, Opera, Vivaldi) and deploy patches as vendors release them
- Review web proxy and endpoint logs for unusual JavaScript execution patterns or sandbox escape attempts between August 4 and patch deployment
- Consider temporary browser isolation or restricted browsing policies for unpatched systems until updates are verified
