On 3 September Google released Chrome 152 with 12 security fixes. For CVE-2026-85046, a type confusion in V8, the company writes that an exploit already exists in the wild. On 4 September CISA added it to the KEV catalogue with a deadline of 18 September.
- Versions 152.0.7977.82/.83 for Windows and Mac and 152.0.7977.82 for Linux.
- CVE-2026-85046 is rated high; it was reported on 4 August by Salvatore Gulizia.
- CISA notes it can affect other Chromium browsers too, including Microsoft Edge and Opera.
Restart your browser. That is the whole instruction, and that is exactly why we skip it.
Google writes that the update will reach people over the coming days and weeks. For a flaw already in use, weeks is a long time. Do not wait for it to arrive on its own.
The important part is further down in CISA's text: the code runs inside the sandbox. By that description, this flaw alone does not get out of the sandbox to the operating system. The bug details, however, may stay restricted until most people have updated, and Google says so explicitly.
Open Settings, then About Chrome, and check that the version is 152.0.7977.82 or higher. In Edge and Opera check their menus the same way for a pending update. Two minutes.