Tech

Chrome Closes a Hole Already Being Exploited: Twelve Fixes in One Update

Version 152.0.7977.82 shipped on 3 September for Windows, Mac, Linux and Android.

Google issued a stable channel update for Chrome on the desktop on 3 September 2026, numbered 152.0.7977.82 and .83 for Windows and Mac and 152.0.7977.82 for Linux. It carries twelve security fixes, ten of them rated High.

The one being exploited now

Google’s own wording is that it is aware an exploit for CVE-2026-85046 exists in the wild. It is a type confusion in V8, Chrome’s JavaScript engine, rated High. That makes the update not optional: open the Chrome menu, then Help, then About Google Chrome, and let the browser restart.

Where the rest landed

  • V8, twice.
  • Compositing, twice.
  • An out-of-bounds write in WebGL.
  • Use-after-free in Skia and in DevTools.
  • Network, CacheStorage and crash reporting.

Chrome for Android moved to the same number on the same day. Two days earlier, on 1 September, version 152.0.7977.75 had already closed twenty-six.

What Google does not say

Google withholds bug details until a majority of users have updated, so there is no technical description of the exploit, no attribution and no victim count. The version number may well have moved past 152 by the time you read this; what matters is being on 152.0.7977.82 or later.

Photo: A laptop and a mug on a wooden desk. Photograph by Ryan Riggins, CC0 via Wikimedia Commons.

Source: Chrome Releases blog, Google, 3 September 2026.

Kuwait One, once a week.

The most useful stories we published this week, in your inbox.

No spam. Unsubscribe anytime.

Leave a comment

Your email will not be published. Comments are reviewed before they appear.