Chrome V8 Zero-Day Under Attack Gets Emergency Patch
Google patches a high-severity type confusion bug in V8 that has been exploited in the wild, the sixth zero-day fixed this year.
Google on Thursday issued an emergency security update for its Chrome browser to address a high-severity vulnerability that attackers are already actively exploiting in the wild. The bug, tracked as CVE-2026-85046 and carrying a CVSS score of 8.8, is a type confusion flaw in V8, the engine that powers Chrome's JavaScript and WebAssembly handling. The disclosure marks the sixth Chrome zero-day that Google has rushed to patch in 2026, underscoring the escalating cadence of browser-based attacks this year.
Sources
- The Hacker News Original source
Continue Reading
Texas, Florida Curb License Plate Surveillance
Texas and Florida are dialing back automated license plate reader use, signaling a shift in surveillance policy.
CrowdStrike Falcon Faces New Zero-Day PoC
The researcher known as Nightmare Eclipse has released FalconFlank, a privilege escalation exploit targeting CrowdStrike Falcon via a Windows Office macro feature.
PostgreSQL backup accounts open 12-year backdoor
A 12-year-old PostgreSQL flaw lets low-privilege replication accounts gain superuser access and remote code execution across platforms.