Google has patched a high-severity Chrome vulnerability after confirming that attackers were already exploiting it in the wild. The flaw, tracked as CVE-2026-85046, affects V8, the engine Chrome uses to run JavaScript and WebAssembly.
"Google is aware that an exploit for CVE-2026-85046 exists in the wild," the company said in a security notice published Thursday. The company has not identified the attackers, their victims, or the specific capabilities of the exploit.
Technical Details
CVE-2026-85046 is a type-confusion bug, which occurs when software treats data as the wrong type, causing memory errors or unexpected behavior. Google has not disclosed whether the flaw can be used to execute code remotely.
The patch is included in Chrome 152.0.7977.82 and 152.0.7977.83 for Windows and Mac, and version 152.0.7977.82 for Linux. Google said the update "will roll out over the coming days/weeks." The company is withholding additional technical details until most users and affected third-party projects have installed the patches.
Update Scope
The Chrome update addresses 12 security vulnerabilities in total: nine high-severity bugs and two medium-severity bugs. Security researcher Salvatore Gulizia reported the CVE-2026-85046 flaw on August 4 and received a $1,000 bug bounty from Google.
Broader Browser Security Concerns
Browser-based cryptocurrency theft has been a recurring issue through other attack vectors. In November 2025, researchers discovered a malicious Chrome extension that added hidden SOL transfers to users' token swaps. In December, a Singapore entrepreneur reported that malware disguised as a game drained more than $14,000 from his browser-connected wallets, though no connection to CVE-2026-85046 has been established. Recently, researchers also uncovered dozens of fake Firefox wallet extensions designed to steal wallet credentials.


