Technology· Cybersecurity

Update Your Browser: Google Patches Chrome Flaw Hackers Were Already Using

Google released a Chrome update addressing a high-severity vulnerability in the V8 JavaScript engine after confirming that attackers were actively exploiting the flaw in the wild. The company has provided limited details about the exploit's scope and impact, including the identities of those responsible and affected users.

By AI NewsroomPublished about 18 hours agoUpdated about 18 hours ago4 views
Update Your Browser: Google Patches Chrome Flaw Hackers Were Already Using

Why It Matters

Active exploitation of browser vulnerabilities poses immediate risk to users, particularly those managing sensitive accounts or assets online. The delayed disclosure of attack details reflects a common security practice of withholding information until patches are widely deployed, balancing transparency against the risk of further harm.

Key Facts

  • Vulnerability ID: CVE-2026-85046
  • Affected Browser: Chrome versions 152.0.7977.82 and 152.0.7977.83
  • Bug Type: Type-confusion flaw in V8 engine
  • Researcher: Salvatore Gulizia (Serotav), awarded $1,000 bounty
  • Total Security Fixes: 12 fixes including 9 high-severity and 2 medium-severity issues

Google has released an emergency security patch for Chrome following confirmation that hackers were already leveraging a critical vulnerability in the browser's V8 engine to conduct attacks. The flaw, identified as CVE-2026-85046, represents a type-confusion bug that can cause memory errors when software incorrectly processes data types. While Google acknowledged the active exploitation in a security notice, the company has declined to disclose specifics about the attackers, their targets, or the full capabilities of the exploit.

The patched version rolls out across Windows, Mac, and Linux systems over the coming weeks, bundled with 11 additional security fixes as part of Chrome's regular update cycle. Security researcher Salvatore Gulizia discovered and reported the vulnerability on August 4, earning a $1,000 bug bounty. Google has withheld detailed technical information about the exploit to allow users and third-party projects time to install patches before more information becomes public.

While this particular vulnerability has not been connected to cryptocurrency theft, browser-based crypto attacks have emerged as a growing threat through other vectors. Recent incidents include malicious Chrome extensions that secretly redirected token transfers, malware disguised as games that drained wallet funds, and counterfeit Firefox extensions designed to harvest wallet credentials. These examples underscore how browser security vulnerabilities and malicious software pose significant risks to users managing financial assets online.

The timing of this patch reflects both the severity of the flaw and Google's security disclosure strategy, which prioritizes rapid patching over immediate transparency. The company has indicated it will share additional details about CVE-2026-85046 only after most users have applied the security update, a standard practice intended to close the window of opportunity for attackers still leveraging the exploit.

Keep Reading