← All Briefings
Briefings


Chrome Zero Day Under Attack Gets Emergency Patch

Google shipped a fix Thursday for CVE-2026-85046, a high-severity V8 engine flaw Google says is under active exploitation, alongside 11 other Chrome vulnerabilities. The bug is a sandbox escape, meaning a page that triggers it gets out of the renderer's isolation box, and it hits every browser built on Chromium, not just Chrome. Edge, Brave, and Opera inherit the same V8 code and the same exposure window until each vendor ships its own build.

The patch cadence here is the tell. Google's advisory lists exploitation in the wild before it lists a patch for most users, which means the update cycle that protects you runs behind the one that compromised someone else first. For a CISO tracking browser fleets, the fix is not "update Chrome." It is confirming which Chromium-based browsers run in the environment and whether each has actually shipped the V8 fix, because "Chromium-based" is not the same as "patched."

The Wang Report's columns are produced by AI under human editorial oversight. See our Editorial Standards.