Google has patched a critical Chrome vulnerability that was confirmed to be exploited, and is now rolling out updates to users on Windows, Mac, and Linux. The vulnerability resides in Chrome's V8 engine and affects how the browser executes JavaScript and WebAssembly.
Unpatched exploitation has been confirmed.
In a security advisory released on Thursday, Google stated that exploit code for CVE-2026-85046 is being actively used in the wild. However, Google has not disclosed the identity of the attackers, the scope of affected victims, or the potential consequences of this vulnerability.
- Windows and Mac: 152.0.7977.82 / 152.0.7977.83
- Linux: 152.0.7977.82
- Updates will be rolled out gradually over the coming days to weeks.
The vulnerability is in the V8 engine.
Google describes this issue as a "type confusion" vulnerability. Such vulnerabilities typically occur when a program incorrectly handles data types, potentially leading to memory errors or other abnormal behavior. Google has not yet disclosed whether this vulnerability can be exploited for remote code execution.
Security researcher Salvatore Gulizia (alias Serotav) reported this issue on August 4, and Google awarded him a $1,000 bug bounty.
This update fixes 12 issues.
Google stated that this Chrome update includes 12 security fixes, comprising nine high-severity and two medium-severity vulnerabilities. For security reasons, certain technical details will remain undisclosed until most users and affected third-party projects have been updated.
As of now, Google has not specified when it will disclose further information regarding this exploitation incident.
Browser extensions have previously attacked crypto users.
Although Google has not directly linked CVE-2026-85046 to the theft of crypto assets, browsers have long been a key attack vector for crypto users, particularly concerning wallet extensions, exchange accounts, and trading tools.
Public cases show that in November 2025, researchers discovered a malicious Chrome extension that secretly added SOL transfer instructions when users exchanged tokens. A month later, a Singaporean entrepreneur reported that malware disguised as a game drained over $14,000 from their browser-connected wallet. Additionally, in August of this year, researchers uncovered dozens of counterfeit Firefox wallet extensions designed to steal wallet credentials.
