On 3 September 2026, Google’s Chrome Releases blog updated desktop Stable to 152.0.7977.82 and 152.0.7977.83 on Windows and Mac, and 152.0.7977.82 on Linux. The high-severity item is CVE-2026-85046, a type confusion bug in V8. Google wrote that an exploit exists in the wild. Salvatore Gulizia (Serotav) reported it on 4 August 2026.
That sentence is the procurement fact. Chrome is the public clock. Every other V8 browser in the fleet inherits the same engine class of bug and ships on its own cadence. A helpdesk screenshot of chrome://version does not tell you whether Edge or Brave has taken the fix.
What Google published, and what it withheld
The Stable note lists CVE-2026-85046 as High and says Google is aware of an in-the-wild exploit. As usual for an actively used bug, the company did not publish a technical write-up that would help someone rebuild the attack. Bookmarkit is not going to fill that gap. If you need the mechanism, wait for a post-patch analysis from a vendor you already trust.
- Affected surface: V8, the JavaScript and WebAssembly engine in Chrome and other Chromium browsers.
- Fixed in: Chrome Stable 152.0.7977.82/.83 (Windows, Mac) and 152.0.7977.82 (Linux), rolling out over days and weeks.
- Reporter and date: Salvatore Gulizia, 4 August 2026, per the Stable note.
- Status: Google states an exploit exists in the wild.
Secondary write-ups, including Security Affairs, called this the sixth actively exploited Chrome zero-day of 2026. Treat that count as reporting, not as a Google headline. The Stable note itself is the source of record for the CVE and the build numbers. On 4 September 2026, CISA added CVE-2026-85046 to the Known Exploited Vulnerabilities catalog. Binding Operational Directive 26-04 applies to federal civilian agencies. CISA still tells every other organization to prioritize KEV items.
What that means for Edge, Brave, and the rest of the V8 family
Microsoft Edge, Brave, Opera, and Vivaldi build on Chromium. They do not update when Chrome updates. They pull the same V8 fix when their own release trains pick it up. Firefox and Safari use different engines, so this CVE is not their bug. An agentic browser sitting on Chromium still needs the engine patch before you debate prompt-injection defenses.
- Record chrome://version (or the managed equivalent) for Chrome, then do the same in Edge and every other Chromium browser your policy allows.
- Check each vendor’s security release after 3 September 2026. Do not assume a Chrome badge means the fork is current.
- For managed fleets, confirm the update ring actually reached 152.0.7977.82 or newer. A pinned older Stable is still exposed.
- If you run an AI browser or a Chromium shell such as Arc or Perplexity, ask which Chromium revision it is on this week.
Put Chrome on the shortlist as infrastructure, not as a feature grid
Bookmarkit added a Google Chrome profile so a browser CVE has a place to live next to ChatGPT and Claude instead of disappearing into a status email. Compare it with Arc or Perplexity when the question is the shell. Compare it with the Chromium forks when the question is time-to-patch.
