Google patches high-severity Chrome flaw actively exploited in the wild
Quick Look
- Google has patched a high-severity Chrome vulnerability (CVE-2026-85046) after discovering attackers were already exploiting it.
- The type-confusion flaw in the V8 JavaScript engine affects Windows, Mac, and Linux versions.
- Google awarded a $1,000 bug bounty to researcher Salvatore Gulizia for reporting the issue on August 4, 2025, but has not identified attackers, victims, or the exploit's capabilities.
AI-generated summary
Why It Matters
Google regularly releases Chrome security updates to address vulnerabilities. The V8 engine is responsible for executing JavaScript and WebAssembly in Chrome. Type-confusion bugs can lead to memory corruption and potential remote code execution if exploited.
Google has patched a high-severity Chrome flaw after finding that attackers were already using it.
The bug affects V8, which Chrome uses to run JavaScript and WebAssembly. Google has not identified the attackers, their victims, or what the exploit can do.
“Google is aware that an exploit for CVE-2026-85046 exists in the wild,” the company said in a security notice published Thursday. “We would also like to thank all security researchers that worked with us during the development cycle to prevent security bugs from ever reaching the stable channel.”
The patch is included in Chrome 152.0.7977.82 and 152.0.7977.83 for Windows and Mac, and version 152.0.7977.82 for Linux. Google said the update “will roll out over the coming days/weeks.”
CVE-2026-85046 is a type-confusion bug. Such flaws occur when software treats data as the wrong type, causing memory errors or other unexpected behavior. Google has not said whether this bug can be used to run code remotely.
Security researcher Salvatore Gulizia, also known as Serotav, reported the flaw on Aug. 4. Google awarded him a $1,000 bug bounty.
Google listed nine high-severity and two medium-severity bugs among the update’s 12 security fixes but is withholding some details until most users—and affected third-party projects—have installed patches.
Google has not said when it will publish more information about the exploit.
Browser-based crypto theft
While Google has not tied CVE-2026-85046 to attacks on crypto users, browser wallets, exchange accounts and trading extensions have been targeted through other methods.
In November 2025, researchers found that a malicious Chrome extension added hidden SOL transfers to users’ swaps.
What to Watch
AI outlook — possibilities, not facts
Google will release more detailed technical information about CVE-2026-85046 after sufficient patch deployment
Likely · Within weeks
Open Questions
- Who are the attackers exploiting CVE-2026-85046?
- What are the victims of the active exploitation?
- What specific capabilities does the exploit provide to attackers?
- Can CVE-2026-85046 be used for remote code execution?







