Affected Systems

Google Chrome versions prior to 152.0.7977.82/.83 (Windows/macOS) and 152.0.7977.82 (Linux). Chromium-based browsers (Microsoft Edge, Brave, Opera, Vivaldi) also affected pending vendor updates. Vulnerability is a type confusion flaw in the V8 JavaScript engine (CVE-2026-85046).

Exploitation Status

Actively exploited in the wild. Exploit confirmed by Google. No technical details disclosed. Likely triggered via malicious JavaScript in crafted HTML pages, enabling remote code execution within Chrome's sandboxed renderer process.

Business Impact

High-severity type confusion in V8 engine allows attackers to corrupt memory and potentially execute code via malicious web pages. This is the sixth Chrome zero-day exploited in 2026. Organizations with Chrome deployments face immediate risk of compromise through drive-by attacks. Chromium-based browser users (Edge, Brave, Opera, Vivaldi) remain vulnerable until vendors release patches, typically within 2-3 days.

Urgency

🔴 Immediate

Recommended Actions

  • Update Google Chrome immediately to version 152.0.7977.82 or later via Settings > About Chrome; restart browser after update completes
  • Deploy Chrome updates via enterprise management tools (GPO, SCCM, Intune) to ensure organization-wide coverage within 24 hours
  • Monitor for updates to Chromium-based browsers (Edge, Brave, Opera, Vivaldi) and apply as soon as vendors release patched versions
  • Review web proxy and endpoint logs for suspicious JavaScript execution or renderer process crashes that may indicate exploitation attempts
  • Consider temporary network-level restrictions on high-risk user groups accessing untrusted websites until patching is complete