Future TechnologyFuture Technology
"Chrome's JavaScript engine had a hole attackers were already using"
CHROME V8 ZERO-DAY

"Chrome's JavaScript engine had a hole attackers were already using"

· 3 min read · By Future Technology

Key takeaways

  • Restart every Chromium-based browser this week to apply the fix
  • The bug affects Edge, Brave and Opera too, not just Chrome
  • Active exploitation suggests a targeted, skilled attacker

What happened

Google pushed an emergency Chrome update this week to close CVE-2026-85046, a type confusion vulnerability in V8, the engine that runs every piece of JavaScript on every website you visit in Chrome. Google rated it high severity, CVSS 8.8, and confirmed it has already been exploited in the wild before the fix shipped. The update was bundled into a broader release covering 12 vulnerabilities.

Type confusion bugs happen when code treats a piece of data as one type when it is actually another, and V8 miscalculates what it is allowed to do with it. Attackers who understand the flaw can use a booby-trapped web page to run their own code inside the browser, no download or click required beyond loading the page.

Why this one travels further than Chrome

V8 is not exclusive to Chrome. It powers every Chromium-based browser, which by September 2026 means Microsoft Edge, Brave, Opera and a long list of smaller browsers built on the same open-source base. A V8 bug found in Chrome tends to get patched across that whole family within days, but only if each vendor ships its own update promptly. Anyone running an older or less actively maintained Chromium browser is at higher risk of sitting exposed for longer.

Active exploitation of a browser rendering engine bug is also notable because it is the kind of flaw historically associated with targeted attacks, spyware vendors and nation-state actors rather than opportunistic criminals, given the skill required to weaponise it reliably. Google has not published details of who is behind the exploitation or who was targeted, which is standard practice while the update rolls out broadly.

What to do about it

Open Chrome's menu, go to Help, then About Google Chrome. If an update is available it will install and prompt for a restart, do that restart immediately rather than leaving dozens of tabs open indefinitely. The same applies to Edge, Brave or any other Chromium browser you use, check each one separately since they update independently.

Browsers that have been left running for weeks without a restart are the most exposed, since the update only takes effect once the browser process restarts. If you manage browsers across an organisation, push the update through your device management tooling rather than waiting for individual users to notice the prompt.

Takeaway: restart every Chromium-based browser you use this week. The fix for CVE-2026-85046 does nothing until you do.

Sources

    The biggest tech story, explained in 3 minutes every weekday. Choose your briefings →

    Free. No spam. Unsubscribe in one click.

    More from Future Technology