Replace Your Browser: Google Patches Chrome Flaw Hackers Had been Already Utilizing – Decrypt




In short
Google confirmed that CVE-2026-85046 is being exploited.
The Chrome replace consists of 12 safety fixes.
Google has not linked the assaults to cryptocurrency theft—but.
Google has patched a high-severity Chrome flaw after discovering that attackers had been already utilizing it.The bug impacts V8, which Chrome makes use of to run JavaScript and WebAssembly. Google has not recognized the attackers, their victims, or what the exploit can do.Myriad: Who wins BLAST Open Porto 2026? Click on to make your prediction.“Google is conscious that an exploit for CVE-2026-85046 exists within the wild,” the corporate mentioned in a safety discover printed Thursday. “We might additionally prefer to thank all safety researchers that labored with us throughout the improvement cycle to stop safety bugs from ever reaching the steady channel.”The patch is included in Chrome 152.0.7977.82 and 152.0.7977.83 for Home windows and Mac, and model 152.0.7977.82 for Linux. Google mentioned the replace “will roll out over the approaching days/weeks.”CVE-2026-85046 is a type-confusion bug. Such flaws happen when software program treats information because the improper kind, inflicting reminiscence errors or different surprising habits. Google has not mentioned whether or not this bug can be utilized to run code remotely.Safety researcher Salvatore Gulizia, also referred to as Serotav, reported the flaw on Aug. 4. Google awarded him a $1,000 bug bounty.Google listed 9 high-severity and two medium-severity bugs among the many replace’s 12 safety fixes however is withholding some particulars till most customers—and affected third-party initiatives—have put in patches.Google has not mentioned when it is going to publish extra details about the exploit.Browser-based crypto theftWhile Google has not tied CVE-2026-85046 to assaults on crypto customers, browser wallets, change accounts and buying and selling extensions have been focused via different strategies.In November 2025, researchers discovered {that a} malicious Chrome extension added hidden SOL transfers to customers’ swaps.A month later, a Singapore entrepreneur mentioned malware disguised as a recreation drained greater than $14,000 from his browser-connected wallets. He believed the assault concerned stolen authentication tokens and an earlier Chrome zero-day; nevertheless, no hyperlink to CVE-2026-85046 has been reported. Extra just lately, in August, researchers additionally uncovered dozens of faux Firefox pockets extensions that stole pockets credentials.Day by day Debrief NewsletterStart day by day with the highest information tales proper now, plus unique options, a podcast, movies and extra.