Chrome
Google patched 12 Chrome vulnerabilities on 3 September including CVE-2026-85046, a type confusion bug in V8 already being exploited, the sixth such flaw this year. Eight days later the Cyber Resilience Act starts requiring manufacturers to report actively exploited vulnerabilities within 24 hours of becoming aware.
Google patched 12 vulnerabilities in Chrome on 3 September, most of them high severity. One was already being used in attacks, TechRadar reported.
The bug is CVE-2026-85046, a type confusion flaw in V8, Chrome’s JavaScript engine. It carries a CVSS score of 8.8 and lets a remote attacker run code inside the sandbox through a crafted web page.
The fixed builds are 152.0.7977.82 and .83. Google’s release notes say an exploit exists in the wild, and the company withheld the details until most browsers are patched.
It is the sixth actively exploited Chrome zero-day this year. Every Chromium browser inherits the flaw, so Edge, Brave, Opera and Vivaldi need the same update, and the rollout is gradual rather than instant.
Salvatore Gulizia reported the bug on 4 August and was paid $1,000. Chrome’s programme pays up to $250,000.
Google has not explained the figure. Reward levels turn on report quality and on whether somebody else found the same bug first, and the company says nothing about either.
The timing is what makes this patch worth more than a version number.
Eight days after it shipped, the rules change for anyone selling software into Europe. Chrome is a product with digital elements.
The Cyber Resilience Act starts applying its reporting obligations on 11 September. Manufacturers must report actively exploited vulnerabilities and severe incidents.
An early warning is due within 24 hours of becoming aware. A full notification follows within 72 hours, and a final report within 14 days once a corrective measure exists.
Reports go through a single platform to the relevant national response team and to ENISA at the same time, which then passes them to every country where the product is sold. TNW has looked at what that 24-hour clock does to software supply chains.
The clock starts at awareness of exploitation, not at a bug report. Google knew by 3 September at the latest, because it said so in public.
Nothing about this patch broke any rule, because the rule was not yet in force. From next week the same sequence becomes a filing, at a company that recently signed a letter calling for cyber defence to be treated as a leadership priority.
Get the TNW newsletter
Get the most important tech news in your inbox each week.