Google addresses several Chrome vulnerabilities, including a V8 security issue that is being exploited in attacks.
On 3 September, Google addressed 12 vulnerabilities in Chrome, including CVE-2026-85046, a type confusion error in V8 that was already being exploited, marking it as the sixth such vulnerability this year. Eight days later, the Cyber Resilience Act will mandate manufacturers to report actively exploited vulnerabilities within 24 hours of discovery.
The vulnerabilities patched on 3 September predominantly had high severity ratings, with one actively being utilized in attacks, according to TechRadar. This vulnerability, CVE-2026-85046, relates to a type confusion flaw in Chrome’s JavaScript engine, V8, and has a CVSS score of 8.8, allowing remote attackers to execute code within the sandbox via a specially crafted web page.
The updated versions are 152.0.7977.82 and .83. According to Google's release notes, an exploit was already in the wild, and the company chose to withhold specific details until most browsers were updated.
This represents the sixth zero-day vulnerability being actively exploited in Chrome this year. Other Chromium-based browsers such as Edge, Brave, Opera, and Vivaldi are also affected, requiring the same updates, which will be rolled out gradually.
Salvatore Gulizia reported the issue on 4 August and received $1,000 in reward. Chrome’s program offers rewards of up to $250,000. Google has not provided an explanation for the amount, as reward levels depend on report quality and whether others discovered the same issue first, which the company has not commented on.
The timing of this patch is notable, as it has implications beyond just a version update. Eight days after its release, new regulatory requirements come into effect for software sold in Europe. Chrome, as a product containing digital elements, falls under the jurisdiction of the Cyber Resilience Act, which begins its reporting obligations on 11 September. Manufacturers must report actively exploited vulnerabilities and significant incidents.
Companies are required to provide an initial warning within 24 hours of awareness, followed by a complete notification within 72 hours, and a final report within 14 days once a corrective measure is implemented. These reports will be submitted through a single platform to the relevant national response team and ENISA simultaneously, which will distribute them to all countries where the product is available. TNW has analyzed how this 24-hour deadline affects software supply chains.
The countdown begins upon awareness of the exploitation, not from the initial bug report. Google was aware by 3 September at the latest, as it indicated publicly. This patch does not violate any rules since the regulation was not yet effective at that time. However, from the following week, this sequence will indeed become part of the reporting obligations for a company that recently signed a letter urging that cyber defense be prioritized by leadership.
Other articles
Google addresses several Chrome vulnerabilities, including a V8 security issue that is being exploited in attacks.
The sixth exploited zero-day in Chrome for the year was fixed on September 3. On September 11, the Cyber Resilience Act begins a 24-hour countdown.
