Google Patches Actively Exploited Chrome Vulnerability CVE-2026-85046
Google released an emergency Chrome update after confirming a V8 type-confusion bug was being exploited in the wild.
Why it matters
Chrome is the most widely used browser, and an actively exploited vulnerability in its V8 engine poses broad risk. Google is withholding details until most users and affected third parties have installed patches, suggesting the flaw may have significant implications.
Key facts
Google confirmed CVE-2026-85046 is being exploited in the wild.
Reported by Decrypt
The vulnerability is a type-confusion bug in V8, Chrome's JavaScript and WebAssembly engine.
Reported by Decrypt
The patch is included in Chrome 152.0.7977.82 and 152.0.7977.83 for Windows and Mac, and version 152.0.7977.82 for Linux.
Reported by Decrypt
Security researcher Salvatore Gulizia reported the flaw on Aug. 4 and received a $1,000 bug bounty.
1,000 USDReported by Decrypt
Google has not identified the attackers, their victims, or whether the exploit can be used for remote code execution.
Reported by Decrypt
Google has not linked the attacks to cryptocurrency theft.
Reported by Decrypt
What happened
Google confirmed that a high-severity Chrome vulnerability, CVE-2026-85046, is being actively exploited by unknown attackers. The flaw is a type-confusion bug in V8, Chrome's JavaScript and WebAssembly engine, which can cause memory errors or other unexpected behavior. Security researcher Salvatore Gulizia reported the bug on Aug. 4 and received a $1,000 bounty. Google released patches in Chrome version 152.0.7977.82 and 152.0.7977.83 for Windows and Mac, with a Linux patch at 152.0.7977.82, and said the update will roll out over the coming days and weeks. The update includes 12 security fixes, nine of which are high-severity and two medium-severity. Google has not identified the attackers, their victims, or whether the exploit can be used for remote code execution, and has not linked the attacks to cryptocurrency theft.
How the story developed
- First report
First report by Decrypt
Update Your Browser: Google Patches Chrome Flaw Hackers Were Already Using
- Update
Salvatore Gulizia reported the flaw
Security researcher Salvatore Gulizia, also known as Serotav, reported the type-confusion bug to Google.
- Official statement
Google published security notice confirming active exploitation
Google announced in a security notice that an exploit for CVE-2026-85046 exists in the wild and released patches.
Affected entities
Original sources
| Publisher | Report | Role | Published |
|---|---|---|---|
| Decrypt Crypto media | Update Your Browser: Google Patches Chrome Flaw Hackers Were Already Using | Original |