Google Patches Multiple Chrome Bugs, Including a V8 Flaw Being Used in Attacks
Google patched 12 Chrome vulnerabilities on 3 September, including CVE-2026-85046, a type confusion bug in V8 already being exploited—the sixth such flaw this year.
The Details:
-
CVE-2026-85046: A type confusion flaw in V8, Chrome’s JavaScript engine, carrying a CVSS score of 8.8. It allows a remote attacker to run code inside the sandbox through a crafted web page.
-
Payment for Bug Reporting: Salvatore Gulizia reported the bug on 4 August and was paid $1,000 as part of Chrome’s bug bounty program, which offers up to $250,000.
-
Timing: The patch arrives just eight days before the Cyber Resilience Act takes effect on 11 September. This act requires manufacturers to report actively exploited vulnerabilities and severe incidents within 24 hours of becoming aware.
In Summary: This patch is significant not only for fixing a critical vulnerability but also for aligning with the upcoming regulatory changes in Europe.