Update Your Browser: Google Patches Chrome Flaw Hackers Were Already Using

Sep 05, 2026 - 19:15
0 0
Update Your Browser: Google Patches Chrome Flaw Hackers Were Already Using

In brief

  • Google confirmed that CVE-2026-85046 is being exploited.
  • The Chrome update includes 12 security fixes.
  • Google has not linked the attacks to cryptocurrency theft—yet.

Google has patched a high-severity Chrome flaw after finding that attackers were already using it.

The bug affects V8, which Chrome uses to run JavaScript and WebAssembly. Google has not identified the attackers, their victims, or what the exploit can do.

 Who wins BLAST Open Porto 2026? Click to make your prediction.Myriad: Who wins BLAST Open Porto 2026? Click to make your prediction.

“Google is aware that an exploit for CVE-2026-85046 exists in the wild,” the company said in a security notice published Thursday. “We would also like to thank all security researchers that worked with us during the development cycle to prevent security bugs from ever reaching the stable channel.”

The patch is included in Chrome 152.0.7977.82 and 152.0.7977.83 for Windows and Mac, and version 152.0.7977.82 for Linux. Google said the update “will roll out over the coming days/weeks.”

CVE-2026-85046 is a type-confusion bug. Such flaws occur when software treats data as the wrong type, causing memory errors or other unexpected behavior. Google has not said whether this bug can be used to run code remotely.

Security researcher Salvatore Gulizia, also known as Serotav, reported the flaw on Aug. 4. Google awarded him a $1,000 bug bounty.

Google listed nine high-severity and two medium-severity bugs among the update’s 12 security fixes but is withholding some details until most users—and affected third-party projects—have installed patches.

Google has not said when it will publish more information about the exploit.

Browser-based crypto theft

While Google has not tied CVE-2026-85046 to attacks on crypto users, browser wallets, exchange accounts and trading extensions have been targeted through other methods.

In November 2025, researchers found that a malicious Chrome extension added hidden SOL transfers to users’ swaps.

A month later, a Singapore entrepreneur said malware disguised as a game drained more than $14,000 from his browser-connected wallets. He believed the attack involved stolen authentication tokens and an earlier Chrome zero-day; however, no link to CVE-2026-85046 has been reported. More recently, in August, researchers also uncovered dozens of fake Firefox wallet extensions that stole wallet credentials.

Daily Debrief Newsletter

Start every day with the top news stories right now, plus original features, a podcast, videos and more.

What's Your Reaction?

Like Like 0
Dislike Dislike 0
Love Love 0
Funny Funny 0
Wow Wow 0
Sad Sad 0
Angry Angry 0

Comments (0)

User