Chrome for Android has been updated to build 152.0.7977.82, and it carries the fix for a V8 vulnerability that Google says attackers are already using. The flaw is tracked as CVE-2026-85046, a type confusion bug in V8, Chrome’s JavaScript engine. Google’s Chrome Releases blog put it plainly in the 3 September desktop release note:
Google is aware that an exploit for CVE-2026-85046 exists in the wild.
That single line is the reason this is worth acting on rather than ignoring. Most Chrome security updates patch bugs found by researchers before anyone weaponizes them. This one is already out there.

What the Chrome for Android update actually includes
The Android release note itself is short, describing only stability and performance improvements. The security detail sits in a standing cross-reference line in the same post: Android releases contain the same security fixes as their corresponding desktop releases, unless Google notes otherwise. The corresponding desktop release here is 152.0.7977.82/.83 on Windows and Mac, and 152.0.7977.82 on Linux.
So the Android build number to look for is 152.0.7977.82. Do not go looking for .83 on your phone — that suffix belongs to the Windows and Mac builds only.
That desktop release ships 12 security fixes in total. Alongside the exploited bug, it patches a second V8 issue, CVE-2026-85045, a race condition that Google has not described as exploited. CVE-2026-85046 was reported by Salvatore Gulizia, who uses the nickname Serotav, on 4 August, and earned a $1,000 bounty.
Google restricts the technical write-up for now. Its own note on the release says access to bug details and links may be kept restricted until a majority of users are updated with a fix. In other words, there is nothing more to read yet, by design.
How to check your Chrome version and force the update
Google says the Android build will become available on Google Play over the next few days. That phrasing matters. This is a staged Play Store rollout, not an instant push, so your phone may sit on an older build for a while even though a fix for a live exploit exists.
- Open Chrome, tap the three-dot menu, then Settings and scroll to About Chrome to read your current version.
- If it is below 152.0.7977.82, open the Google Play Store.
- Search for Chrome and open its listing directly. Tap Update if the button appears.
- If Play still shows only Open, the build has not reached your device yet. Check again over the next couple of days.
Closing and reopening all your tabs after updating is worth doing too. A running Chrome process keeps the old code loaded until the browser is fully restarted.
The part Google does not spell out
A staggered rollout is normal engineering practice. It is also the weakest part of this story for the person holding the phone. Google publishes the existence of an active exploit on day one, then delivers the patch on Play’s own schedule over several days. There is no user-facing switch to jump the queue on Android, unlike on desktop where you can trigger the update yourself from the About page.
Chrome’s patch pipeline has been moving quickly this year, including the large AI-assisted bug-fixing effort Google described in July. Delivery to Android phones is still the slow link in that chain. Until your build reads 152.0.7977.82, checking the Play Store listing manually is the only thing that speeds it up.





