Google has patched a high-severity Chrome vulnerability after confirming that attackers were already using it in the wild.

Zero-day activity confirmed by Google
In a security notice published Thursday, Google said: "Google is aware that an exploit for CVE-2026-85046 exists in the wild." The company added that it wanted to thank the security researchers who worked with it during the development cycle to keep security bugs from reaching the stable channel.
The flaw affects V8, the engine Chrome uses to run JavaScript and WebAssembly. Google has not identified the attackers, disclosed any victims, or said what the exploit can do.
Patched versions and rollout timeline
The fix is included in the following Chrome releases:
- Windows and Mac: Chrome 152.0.7977.82 and 152.0.7977.83
- Linux: Chrome 152.0.7977.82
Google said the update will roll out over the coming days and weeks.
What is known about CVE-2026-85046
CVE-2026-85046 is a type-confusion bug. These flaws happen when software handles data as the wrong type, which can trigger memory errors or other unexpected behavior. Google has not said whether the bug can be used for remote code execution.
Security researcher Salvatore Gulizia, also known as Serotav, reported the issue on Aug. 4. Google awarded him a $1,000 bug bounty.
Among the 12 security fixes included in the update, Google listed nine high-severity bugs and two medium-severity bugs. The company is withholding some details until most users, along with affected third-party projects, have installed patches.
Google has not said when it plans to publish more information about the exploit.
Crypto theft through browsers remains a live risk
Google has not tied CVE-2026-85046 to attacks on crypto users. Even so, browser wallets, exchange accounts, and trading extensions have been targeted through other methods.
In November 2025, researchers found that a malicious Chrome extension inserted hidden SOL transfers into users’ swaps.
A month later, a Singapore entrepreneur said malware disguised as a game drained more than $14,000 from wallets connected through his browser. He said he believed the attack involved stolen authentication tokens and an earlier Chrome zero-day. No link to CVE-2026-85046 has been reported.
More recently, in August, researchers also uncovered dozens of fake Firefox wallet extensions designed to steal wallet credentials.

