Saturday, September 5, 2026

Key Details

  • Google has confirmed that CVE-2026-85046 is currently being exploited in the wild.
  • The Chrome update addresses twelve security issues.
  • Google has not yet connected these attacks to cryptocurrency theft.

Google has patched a high‑severity Chrome vulnerability after discovering that attackers were already exploiting it.

The flaw resides in Chrome’s V8 engine, which executes JavaScript and WebAssembly. Google has not identified the attackers, their targets, or the exact capabilities of the exploit.

Google acknowledged that an exploit for CVE-2026-85046 is active in the wild, stating in a Thursday security notice, ‘We also thank all security researchers who collaborated with us during development to keep such bugs from reaching the stable channel.’

The fix is part of Chrome versions 152.0.7977.82 and 152.0.7977.83 for Windows and macOS, and version 152.0.7977.82 for Linux. Google noted that the update will be rolled out over the coming days and weeks.

CVE‑2026‑85046 is a type‑confusion vulnerability, which arises when software interprets data as an incorrect type, potentially leading to memory errors or other unpredictable behavior. Google has not disclosed whether the flaw allows remote code execution.

Security researcher Salvatore Gulizia, also known as Serotav, reported the issue on August 4, and Google granted him a $1,000 bug bounty.

Among the twelve security fixes in this release, Google identified nine as high‑severity and two as medium‑severity, though it is withholding certain details until most users and impacted third‑party projects have applied the patches.

Google has not yet announced when it will release further details about the exploit.

Browser‑Based Crypto Theft

Although Google has not linked CVE‑2026‑85046 to cryptocurrency‑focused attacks, browser wallets, exchange accounts, and trading extensions have been compromised via other techniques.

In November 2025, researchers discovered a malicious Chrome extension that inserted hidden SOL transfers into users’ token swaps.

A month later, a Singapore entrepreneur reported that malware masquerading as a game drained over $14,000 from his browser‑connected wallets. He suspected the breach involved stolen authentication tokens and a prior Chrome zero‑day, though no connection to CVE‑2026‑85046 has been established. More recently, in August, researchers uncovered dozens of counterfeit Firefox wallet extensions that harvested wallet credentials.



Source link

Exit mobile version