Desert Forge IT — Arizona IT · Field-tested tools & guidesFree consult →

Chrome Zero-Days CVE-2026-85046 & CVE-2026-87491: Update Chrome, Edge, Brave (September 2026)

High CVE-2026-85046, CVE-2026-87491 — Two exploited V8 bugs let a malicious web page run code in Chrome and every Chromium browser on Windows, macOS, Linux, and Android. Fixed Chrome versions and how to update Edge, Brave, and Opera.

Published 2026-10-08 · Last updated 2026-10-08

TL;DR: Visiting a malicious or compromised web page could run attacker code in your browser. Google fixed two actively exploited V8 JavaScript-engine bugs within a week in September. Make sure Chrome is at 153.0.8010.36 or later, and restart it. Edge, Brave, Opera, and Vivaldi share the engine and need their own updates.

CVE-2026-85046V8 type confusion · fixed in Chrome 152.0.7977.82 · KEV 2026-09-04
CVE-2026-87491V8 out-of-bounds write · fixed in Chrome 153.0.8010.36 · KEV 2026-09-09
TriggerJust loading a crafted HTML page; no download or click needed
ImpactCode execution inside the browser sandbox
PlatformsEvery OS Chrome runs on: Windows, macOS, Linux, ChromeOS, Android
Also affectsChromium-based browsers: Microsoft Edge, Brave, Opera, Vivaldi, Arc

What happened

V8 is the engine that runs JavaScript in Chrome and every other Chromium-based browser. In early September Google shipped two emergency fixes for V8 bugs it said were being exploited:

  • CVE-2026-85046: a type confusion, where V8 treats an object as the wrong kind of object and reads or writes memory it shouldn’t.
  • CVE-2026-87491: an out-of-bounds write, where V8 writes past the end of a buffer.

Either one lets a web page run code inside the browser’s sandbox. Attackers usually pair a V8 bug like this with a second “sandbox escape” bug to take over the whole computer, and these chains are often delivered through compromised legitimate sites or malicious ads.

Am I affected?

  • Chrome (desktop): open chrome://settings/help. You need 153.0.8010.36 or later.
  • Edge: edge://settings/help
  • Brave: brave://settings/help · Opera: opera://update
  • Linux: google-chrome --version or chromium --version
  • Android: Play Store → Chrome → Update. Also update Android System WebView, which apps use to show web content.

How to patch

Chrome downloads updates on its own but only applies them when you restart the browser. People who never close Chrome can sit on a vulnerable version for weeks. Open the settings/help page above; it will download the update and show a Relaunch button. Click it.

Linux:

# Debian/Ubuntu with Google's repo
sudo apt update && sudo apt install --only-upgrade google-chrome-stable
# Fedora
sudo dnf upgrade google-chrome-stable
# Flatpak
flatpak update

Businesses: use Chrome or Edge group policy (RelaunchNotification and RelaunchNotificationPeriod) to force a relaunch within a day or two of an update, so a forgotten browser window doesn’t stay vulnerable for weeks.

Earlier this year: CVE-2026-11645 (June)

These weren’t Chrome’s first exploited V8 bugs of the summer. In June, Google fixed CVE-2026-11645, an out-of-bounds read/write in V8 (Chromium severity High) that also allowed code execution inside the sandbox from a crafted page, fixed in Chrome 149.0.7827.103 and added to CISA’s exploited list on 2026-06-09. Any Chrome at 153.0.8010.36 or later includes that fix too.

What about Firefox and Safari?

These two bugs are in V8, which Firefox (SpiderMonkey) and Safari (JavaScriptCore) don’t use, so they’re not affected by these CVEs. Keep them updated anyway. Every browser engine gets zero-days.

Sources

← Back to Knowledge Base

Want this handled for you?

Desert Forge IT patches, monitors, and backs up servers and networks for Phoenix-area businesses. We track advisories like this one so you don’t have to. Get a free consult and we’ll tell you what you’re exposed to.

Get a free security check →  ·  More security advisories