SolanaSOL, coin
DevelopingHack

Google Patches Actively Exploited Chrome Vulnerability CVE-2026-85046

Google released an emergency Chrome update after confirming a V8 type-confusion bug was being exploited in the wild.

Why it matters

Chrome is the most widely used browser, and an actively exploited vulnerability in its V8 engine poses broad risk. Google is withholding details until most users and affected third parties have installed patches, suggesting the flaw may have significant implications.

Key facts

Google confirmed CVE-2026-85046 is being exploited in the wild.

Reported by Decrypt

The vulnerability is a type-confusion bug in V8, Chrome's JavaScript and WebAssembly engine.

Reported by Decrypt

The patch is included in Chrome 152.0.7977.82 and 152.0.7977.83 for Windows and Mac, and version 152.0.7977.82 for Linux.

Reported by Decrypt

Security researcher Salvatore Gulizia reported the flaw on Aug. 4 and received a $1,000 bug bounty.

1,000 USDReported by Decrypt

Google has not identified the attackers, their victims, or whether the exploit can be used for remote code execution.

Reported by Decrypt

Google has not linked the attacks to cryptocurrency theft.

Reported by Decrypt

What happened

Google confirmed that a high-severity Chrome vulnerability, CVE-2026-85046, is being actively exploited by unknown attackers. The flaw is a type-confusion bug in V8, Chrome's JavaScript and WebAssembly engine, which can cause memory errors or other unexpected behavior. Security researcher Salvatore Gulizia reported the bug on Aug. 4 and received a $1,000 bounty. Google released patches in Chrome version 152.0.7977.82 and 152.0.7977.83 for Windows and Mac, with a Linux patch at 152.0.7977.82, and said the update will roll out over the coming days and weeks. The update includes 12 security fixes, nine of which are high-severity and two medium-severity. Google has not identified the attackers, their victims, or whether the exploit can be used for remote code execution, and has not linked the attacks to cryptocurrency theft.

How the story developed

  1. First report

    First report by Decrypt

    Update Your Browser: Google Patches Chrome Flaw Hackers Were Already Using

    Decrypt

  2. Update

    Salvatore Gulizia reported the flaw

    Security researcher Salvatore Gulizia, also known as Serotav, reported the type-confusion bug to Google.

    Decrypt

  3. Official statement

    Google published security notice confirming active exploitation

    Google announced in a security notice that an exploit for CVE-2026-85046 exists in the wild and released patches.

    Decrypt

Affected entities

Original sources

PublisherReportRolePublished
Decrypt
Crypto media
Update Your Browser: Google Patches Chrome Flaw Hackers Were Already UsingOriginal