Google has issued a critical update for Chrome 152 to address a serious security flaw actively being exploited. This update resolves 12 vulnerabilities, notably including a zero-day bug identified as CVE-2026-85046. This high-severity issue, reported by security researcher Salvatore Gulizia, involves a type confusion vulnerability in Chrome’s V8 JavaScript and WebAssembly engine. Type confusion flaws in the V8 engine can potentially allow attackers to execute remote read and write operations by exploiting crafted HTML pages, leading to severe outcomes like crashes or remote code execution. Google acknowledged the existence of active exploits targeting this vulnerability, underscoring the urgency for users to update their browsers immediately. This marks the sixth zero-day vulnerability in Chrome addressed by Google in 2026 alone, highlighting ongoing challenges in maintaining browser security. The latest security updates are available in Chrome versions 152.0.7977.82 and 152.0.7977.83 for Windows and macOS, and version 152.0.7977.82 for Linux. In addition to the zero-day fix, the update also addresses nine other high-severity vulnerabilities, including issues related to out-of-bounds read and write, incomplete cleanup, and improper resource exposure. The patch also covers two medium-severity vulnerabilities related to improper input validation and use-after-free issues. With these updates, Google continues its efforts to protect users by closing gaps that could be exploited by malicious actors.