Google has patched a high-severity Chrome flaw after finding that attackers were already using it.
The bug affects V8, which Chrome uses to run JavaScript and WebAssembly. Google has not identified the attackers, their victims, or what the exploit can do.
Myriad: Who wins BLAST Open Porto 2026? Click to make your prediction.
“Google is aware that an exploit for CVE-2026-85046 exists in the wild,” the company said in a security notice published Thursday. “We would also like to thank all security researchers that worked with us during the development cycle to prevent security bugs from ever reaching the stable channel.”
The patch is included in Chrome 152.0.7977.82 and 152.0.7977.83 for Windows and Mac, and version 152.0.7977.82 for Linux. Google said the update “will roll out over the coming days/weeks.”
CVE-2026-85046 is a type-confusion bug. Such flaws occur when software treats data as the wrong type, causing memory errors or other unexpected behavior. Google has not said whether this bug can be used to run code remotely.
Security researcher Salvatore Gulizia, also known as Serotav, reported the flaw on Aug. 4. Google awarded him a $1,000 bug bounty.
Google listed nine high-severity and two medium-severity bugs among the update’s 12 security fixes but is withholding some details until most users—and affected third-party projects—have installed patches.
Google has not said when it will publish more information about the exploit.
Browser-based crypto theft
While Google has not tied CVE-2026-85046 to attacks on crypto users, browser wallets, exchange accounts and trading extensions have been targeted through other methods.
In November 2025, researchers found that a malicious Chrome extension added hidden SOL transfers to users’ swaps.
A month later, a Singapore entrepreneur said malware disguised as a game drained more than $14,000 from his browser-connected wallets. He believed the attack involved stolen authentication tokens and an earlier Chrome zero-day; however, no link to CVE-2026-85046 has been reported. More recently, in August, researchers also uncovered dozens of fake Firefox wallet extensions that stole wallet credentials.
免责声明:本文章仅代表作者个人观点,不代表本平台的立场和观点。本文章仅供信息分享,不构成对任何人的任何投资建议。用户与作者之间的任何争议,与本平台无关。如网页中刊载的文章或图片涉及侵权,请提供相关的权利证明和身份证明发送邮件到support@aicoin.com,本平台相关工作人员将会进行核查。