
Chrome Zero Day Under Attack Gets Emergency Patch
Kai Tanner on the Chrome zero day under active attack that forces a check of every Chromium browser in your fleet, not just Chrome.
Continue reading
A V8 engine flaw already being exploited forced Google to ship a fix across every Chromium browser this week, not just Chrome.
Google shipped a fix Thursday for CVE-2026-85046, a high-severity V8 engine flaw Google says is under active exploitation, alongside 11 other Chrome vulnerabilities. The bug is a sandbox escape, meaning a page that triggers it gets out of the renderer's isolation box, and it hits every browser built on Chromium, not just Chrome. Edge, Brave, and Opera inherit the same V8 code and the same exposure window until each vendor ships its own build.
The patch cadence here is the tell. Google's advisory lists exploitation in the wild before it lists a patch for most users, which means the update cycle that protects you runs behind the one that compromised someone else first. For a CISO tracking browser fleets, the fix is not "update Chrome." It is confirming which Chromium-based browsers run in the environment and whether each has actually shipped the V8 fix, because "Chromium-based" is not the same as "patched."






