Google has released a Chrome security update to address a high-severity vulnerability that it says attackers were already exploiting. The flaw, tracked as CVE-2026-85046, affects V8, the browser engine Chrome uses to process JavaScript and WebAssembly content.

The company has not identified who used the exploit, who may have been targeted, or what actions the bug may have enabled. It also has not said whether the flaw could be used for remote code execution, leaving key details undisclosed for now.

Patch rollout underway

The fix is included in Chrome 152.0.7977.82 and 152.0.7977.83 for Windows and macOS, and in Chrome 152.0.7977.82 for Linux. Google said the update will continue rolling out over the coming days and weeks.

As is common with actively exploited bugs, the company is limiting technical disclosure while the patched versions reach more users. Google said some details will remain restricted until most users, as well as affected third-party projects, have installed fixes.

What Google disclosed about the bug

Google classified CVE-2026-85046 as a type-confusion issue in V8. This category of flaw appears when software handles data as though it were a different type than it actually is, which can lead to memory corruption or other unintended behavior.

The browser maker has not provided a public technical write-up of the exploit and has not said when fuller information will be released. In the same security update, Google listed 12 fixes in total, including nine high-severity issues and two rated medium severity.

Researcher report and bug bounty

The vulnerability was reported on Aug. 4 by security researcher Salvatore Gulizia, who is also known as Serotav. Google said it awarded a $1,000 bug bounty for the finding.

The company’s advisory confirms only that an exploit exists in the wild. Beyond that, it has not attributed the activity to any group or disclosed a campaign tied to the flaw.

Broader browser risks for crypto users

Google has not linked CVE-2026-85046 to theft targeting cryptocurrency users. Even so, browser-based attacks remain a recurring risk for people who use wallet extensions, exchange logins, and trading tools inside desktop browsers.

Researchers reported in November 2025 that a malicious Chrome extension inserted hidden SOL transfers into users’ swaps. In December 2025, a Singapore entrepreneur said malware disguised as a game drained more than $14,000 from browser-connected wallets; he believed stolen authentication tokens and an earlier Chrome zero-day were involved, but no connection to CVE-2026-85046 has been reported. In August, researchers also found dozens of fake Firefox wallet extensions designed to steal wallet credentials.

What happens next

For now, the confirmed next step is the staged release of the patched Chrome versions across supported platforms. Google has said only that additional exploit details will stay withheld until more users and impacted third-party projects are protected.

The company has not given a date for publishing deeper analysis of the flaw, so the public picture remains limited to the existence of in-the-wild exploitation, the affected component in V8, and the browser versions that contain the fix.

Source: decrypt.co