TechRadar News.
Technology

Google Deploys Rapid Fix for Actively Exploited Chrome Zero-Day Vulnerability

Google Deploys Rapid Fix for Actively Exploited Chrome Zero-Day Vulnerability

Google has released an urgent security update for Chrome to seal a critical zero‑day bug that is already being used by attackers. The flaw, identified as CVE‑2026‑85046, resides in Chrome’s V8 JavaScript and WebAssembly engine, the core component that runs web‑page code.

Researchers first spotted the problem after seeing malicious sites serve payloads that caused arbitrary code execution on vulnerable browsers. Since V8 powers Chrome and other Chromium‑based browsers, the danger affected a wide audience. Google responded by pushing an emergency patch, skipping the normal release cycle to protect users swiftly.

The vulnerability enables an attacker to circumvent Chrome’s sandbox by exploiting a memory‑corruption error in the engine’s processing of specific WebAssembly constructs. Once the sandbox is broken, the malicious code can execute with the user’s privileges, potentially exfiltrating data, installing malware, or taking over the system. Experts caution that the exploit chain is sophisticated enough to run without any user interaction, heightening its risk.

Google is urging all Chrome users to install the update right away, noting that the fix is already being delivered via the browser’s automatic update system on Windows, macOS, Linux, Android, and Chrome OS. Enterprises should confirm that the newest version is rolled out across their devices and watch for unusual activity that might signal a breach before the patch.

The appearance of CVE‑2026‑85046 highlights the continual difficulty of protecting complex web platforms. Although Chrome’s rapid update rhythm usually limits exposure, zero‑day attacks targeting core execution engines remain a constant threat. Analysts anticipate that threat actors will turn to other browsers or search for comparable flaws in related components, demanding ongoing vigilance from vendors and users alike.

TechRadar Desk — Editorial desk.

Comments (0)

Be the first to comment.

Join the discussion

Protected by reCAPTCHA v3

Related