Update Your Browser: Google Patches Chrome Flaw Hackers Were Already Using
The update fixes a high-severity flaw in Chrome’s V8 engine, but Google has not revealed who is using it or whom they targeted.
Jason Nelson
Publisher Decrypt
Sep 5, 2026 at 3:01 PM UTC · 2 min de leitura

- Google confirmed that CVE-2026-85046 is being exploited.
- The Chrome update includes 12 security fixes.
- Google has not linked the attacks to cryptocurrency theft—yet.
Google has patched a high-severity Chrome flaw after finding that attackers were already using it.
The bug affects V8, which Chrome uses to run JavaScript and WebAssembly. Google has not identified the attackers, their victims, or what the exploit can do.

“Google is aware that an exploit for CVE-2026-85046 exists in the wild,” the company said in a security notice published Thursday. “We would also like to thank all security researchers that worked with us during the development cycle to prevent security bugs from ever reaching the stable channel.”
The patch is included in Chrome 152.0.7977.82 and 152.0.7977.83 for Windows and Mac, and version 152.0.7977.82 for Linux. Google said the update “will roll out over the coming days/weeks.”
CVE-2026-85046 is a type-confusion bug. Such flaws occur when software treats data as the wrong type, causing memory errors or other unexpected behavior. Google has not said whether this bug can be used to run code remotely.
Security researcher Salvatore Gulizia, also known as Serotav, reported the flaw on Aug. 4. Google awarded him a $1,000 bug bounty.
Article Intelligence
Topics
Related Coverage
View all relatedSponsored
AdNewsLayer Premium
Unlock deeper intelligence.
Ad-free reading, exclusive research, and real-time onchain insights.
Go Premium
