Google urgently fixes a high-risk Chrome vulnerability that has been exploited
Google urgently fixes a critical security flaw in Chrome after discovering that attackers are actually exploiting the vulnerability. The vulnerability affects the V8 engine, which Chrome uses to run JavaScript and WebAssembly code. As of now, Google has not confirmed the identity of the attacker, the status of the victim and the specific harm of the vulnerability.
Official response and patch details
Google said in a security announcement released on Thursday: "We know that the CVE-2026-85046 vulnerability has been exploited in the wild." At the same time, the company thanked all security researchers who worked with Google during the development cycle to prevent security vulnerabilities from flowing into the stable release channel.
This patch is included in Chrome versions 152.0.7977.82 and 152.0.7977.83 for Windows and Mac, and version 152.0.7977.82 for Linux. Google said updates will be rolled out to users gradually over the next few days to weeks.
Technical details and reward mechanism
CVE-2026-85046 is a Type-Confusion vulnerability. Such flaws typically occur when software mistakenly identifies data as other types, causing memory errors or triggering other unexpected behavior. Currently, Google has not disclosed whether the vulnerability can be used to remotely execute code.
Security researcher Salvatore Gulizia (alias Serotav) reported the vulnerability on August 4 and received a $1,000 vulnerability reward from Google.
Other security updates and industry background
Among the 12 security fixes in this update, Google listed nine high-risk vulnerabilities and two medium-risk vulnerabilities, but some details will not be disclosed for the time being to protect most users and affected third-party projects. Google also did not say when it would release more information about the exploit of the vulnerability.
Although Google has not directly linked CVE-2026-85046 to attacks on cryptocurrency users, browser wallets, exchange accounts, and transaction extensions have previously been targeted through other means:
- In November 2025, researchers discovered that a malicious Chrome extension would secretly add hidden SOL transfer instructions to users 'redemption operations. [TAG A month later, a Singapore entrepreneur said malware disguised as a game stole more than US$14,000 from his browser-connected wallet. He believes the attack involved stolen authentication tokens and an early zero-day vulnerability in Chrome; however, there is currently no evidence of a link to CVE-2026-85046.
- More recently, in August, researchers also discovered dozens of fake Firefox wallet extensions that stole wallet credentials.

Exchange Ranking
Top Exchanges
24h Volume Ranking
Popularity Ranking
Exchange BTC Balance
Proof of Reserves
Decentralized Exchanges
Funding Rate
Funding Heatmap
Liquidation Data
Max Pain
Long/Short Ratio
Whale L/S Ratio
Binance/Okex/Huobi L/S
Bitfinex Margin L/S
ETF Tracker
Solana ETF
XRP ETF
Hong Kong ETF
Bitcoin Treasuries
Crypto Reversal
Ethereum Reserves
HyperLiquid Wallet Analysis
Hyperliquid Whale Watch
Large Transactions
On-chain Movement
Bitcoin ROI
Stablecoin Market Cap
Options Analysis
News
Articles
Economic Calendar
Features
Wallet
Contract Calculator
Security
Collections
Watchlist
Following
SOL