{
  "version": 1,
  "event_id": "evt_6f539d0676332e82",
  "url": "https://xiyu.news/events/evt_6f539d0676332e82/",
  "json": "https://xiyu.news/api/events/evt_6f539d0676332e82.json",
  "type": "security_incident",
  "status": "monitoring",
  "category": "technology",
  "title": {
    "zh": "谷歌修复已被野外利用的 Chrome 零日漏洞 CVE-2026-85046",
    "en": "Update Your Browser: Google Patches Chrome Flaw Hackers Were Already Using"
  },
  "current_state": {
    "zh": "谷歌确认 Chrome 漏洞 CVE-2026-85046（V8 JavaScript 引擎中的一个高危类型混淆漏洞）已在野外被利用。该公司在 Windows 和 Mac 版 Chrome 152.0.7977.82 与 152.0.7977.83 以及 Linux 版 152.0.7977.82 中发布了修复，共包含 12 项安全更新。\n\n被积极利用的 Chrome 零日漏洞可能让大量浏览器用户面临攻击风险，尤其是因为许多人会推迟浏览器更新，而 V8 漏洞影响范围广泛，波及各类基于 Chromium 的浏览器。据报道，这是 2026 年第六个 Chrome 零日漏洞，凸显了此类披露已变得多么频繁。\n\n该漏洞由安全研究员 Salvatore Gulizia 于 8 月 4 日报告并获得 1000 美元漏洞赏金。谷歌尚未公布攻击者、受害者或利用漏洞的完整影响，且在大多数用户及受影响的第三方项目完成修复前，暂缓披露部分细节。",
    "en": "Google patched a high-severity Chrome zero-day (CVE-2026-85046) that was already being exploited in the wild, with the update rolling out across Windows, Mac, and Linux."
  },
  "first_seen_at": "2026-09-05T15:26:14.183548+00:00",
  "last_updated_at": "2026-09-05T15:26:14.183548+00:00",
  "last_material_change_at": "2026-09-05T15:26:14.183548+00:00",
  "confidence": 0.75,
  "updates_count": 1,
  "sources_count": 1,
  "entities": [
    "already",
    "browser",
    "chrome",
    "flaw",
    "google",
    "hackers",
    "patches",
    "update",
    "using",
    "were",
    "your"
  ],
  "identifiers": [
    "cve-2026",
    "cve-2026-85046"
  ],
  "topics": [
    "chrome",
    "cve-2026-85046",
    "google",
    "zero-day"
  ],
  "updates": [
    {
      "update_id": "upd_00851c3684224245",
      "event_id": "evt_6f539d0676332e82",
      "occurred_at": "2026-09-05T15:01:04Z",
      "published_at": "2026-09-05T15:01:04Z",
      "first_seen_at": "2026-09-05T15:26:14.183548Z",
      "time_precision": "published",
      "update_type": "initial",
      "material_change": true,
      "title_zh": "谷歌修复已被野外利用的 Chrome 零日漏洞 CVE-2026-85046",
      "title_en": "Update Your Browser: Google Patches Chrome Flaw Hackers Were Already Using",
      "what_changed_zh": "谷歌确认 Chrome 漏洞 CVE-2026-85046（V8 JavaScript 引擎中的一个高危类型混淆漏洞）已在野外被利用。该公司在 Windows 和 Mac 版 Chrome 152.0.7977.82 与 152.0.7977.83 以及 Linux 版 152.0.7977.82 中发布了修复，共包含 12 项安全更新。\n\n被积极利用的 Chrome 零日漏洞可能让大量浏览器用户面临攻击风险，尤其是因为许多人会推迟浏览器更新，而 V8 漏洞影响范围广泛，波及各类基于 Chromium 的浏览器。据报道，这是 2026 年第六个 Chrome 零日漏洞，凸显了此类披露已变得多么频繁。\n\n该漏洞由安全研究员 Salvatore Gulizia 于 8 月 4 日报告并获得 1000 美元漏洞赏金。谷歌尚未公布攻击者、受害者或利用漏洞的完整影响，且在大多数用户及受影响的第三方项目完成修复前，暂缓披露部分细节。",
      "what_changed_en": "Google patched a high-severity Chrome zero-day (CVE-2026-85046) that was already being exploited in the wild, with the update rolling out across Windows, Mac, and Linux.",
      "current_state_zh": "谷歌确认 Chrome 漏洞 CVE-2026-85046（V8 JavaScript 引擎中的一个高危类型混淆漏洞）已在野外被利用。该公司在 Windows 和 Mac 版 Chrome 152.0.7977.82 与 152.0.7977.83 以及 Linux 版 152.0.7977.82 中发布了修复，共包含 12 项安全更新。\n\n被积极利用的 Chrome 零日漏洞可能让大量浏览器用户面临攻击风险，尤其是因为许多人会推迟浏览器更新，而 V8 漏洞影响范围广泛，波及各类基于 Chromium 的浏览器。据报道，这是 2026 年第六个 Chrome 零日漏洞，凸显了此类披露已变得多么频繁。\n\n该漏洞由安全研究员 Salvatore Gulizia 于 8 月 4 日报告并获得 1000 美元漏洞赏金。谷歌尚未公布攻击者、受害者或利用漏洞的完整影响，且在大多数用户及受影响的第三方项目完成修复前，暂缓披露部分细节。",
      "current_state_en": "Google patched a high-severity Chrome zero-day (CVE-2026-85046) that was already being exploited in the wild, with the update rolling out across Windows, Mac, and Linux.",
      "detailed_summary_zh": "Google patched a high-severity Chrome zero-day (CVE-2026-85046) that was already being exploited in the wild, with the update rolling out across Windows, Mac, and Linux.",
      "detailed_summary_en": "Google patched a high-severity Chrome zero-day (CVE-2026-85046) that was already being exploited in the wild, with the update rolling out across Windows, Mac, and Linux.",
      "background_zh": "类型混淆是指软件将对象当作其实际不属于的数据类型来处理，可能导致内存损坏或意外行为。V8 是谷歌开源的 JavaScript 和 WebAssembly 引擎，用于 Chrome、Node.js 及其他基于 Chromium 的浏览器，因此其中的漏洞影响尤其重大。",
      "background_en": "Type confusion occurs when software treats an object as a data type it does not actually have, which can lead to memory corruption or unexpected behavior. V8 is Google's open-source JavaScript and WebAssembly engine used in Chrome, Node.js, and other Chromium-based browsers, making vulnerabilities there especially impactful.",
      "community_discussion_zh": "",
      "community_discussion_en": "",
      "market_impact_zh": "谷歌尚未将此漏洞与加密货币盗窃相关联，因此目前没有明确直接影响数字资产市场的传导渠道。该事件主要影响基于浏览器的钱包和交易所用户的安全态势，只有当后续报告将此漏洞与加密货币相关攻击联系起来时，才可能出现针对加密领域的市场影响。",
      "market_impact_en": "Google has not tied this vulnerability to cryptocurrency theft, so there is no identified direct transmission channel to digital asset markets. The story mainly affects security posture for browser-based wallets and exchange users, and any crypto-specific market impact would only materialize if later reports connect this exploit to cryptocurrency-related campaigns.",
      "importance_score": 7.5,
      "references": [
        {
          "url": "https://shattered.io/chrome-zero-day-cve-2026-85046-sixth-2026/",
          "title": "Chrome Zero-Day CVE-2026-85046: 6th of 2026, CVSS 8.8"
        },
        {
          "url": "https://blog.gridinsoft.com/chrome-cve-2026-85046-update/",
          "title": "Chrome CVE-2026-85046: Update and Verify Your Browser"
        },
        {
          "url": "https://www.huntress.com/cybersecurity-101/topic/type-confusion",
          "title": "What Is Type Confusion and How Does It Work? | Huntress"
        }
      ],
      "confidence": 0.75,
      "story_ids": [
        "rss:decrypt.co_feed:28dc26bc566b81bc"
      ],
      "sources": [
        {
          "url": "https://decrypt.co/377501/google-chrome-zero-day-exploited",
          "label": "Decrypt",
          "source_type": "rss",
          "official": false
        }
      ]
    }
  ]
}
