"Chrome's JavaScript engine had a hole attackers were already using"
Future Technology
New article published
CHROME V8 ZERO-DAY
"Chrome's JavaScript engine had a hole attackers were already using"
Google pushed an emergency Chrome update this week to close CVE-2026-85046, a type confusion vulnerability in V8, the engine that runs every piece of JavaScript on every website you visit in Chrome. Google rated it high severity, CVSS 8.8, and confirmed it has already been exploited in the wild before the fix shipped. The update was bundled into a broader release covering 12 vulnerabilities.
Key Takeaways
- Restart every Chromium-based browser this week to apply the fix
- The bug affects Edge, Brave and Opera too, not just Chrome
- Active exploitation suggests a targeted, skilled attacker
You received this because you subscribe to Future Technology.