All NewsEducationTVBrokers
Equities & FundsCrypto & Digital AssetsAI & TechnologyBusiness & CorporateUS Politics & PolicyGeopolitics & Global RiskMacro, Rates & FXCommodities & EnergyEuropean Politics & MarketsAsia-PacificReal Estate & Property
All NewsHome
← Back to AI & Technology

Google Patches Chrome Flaw Exploited by Hackers

Created at 5 Sep · 3:06 PM1 source↑ Market-relevant
IN SHORT

Google has released a Chrome update to fix a high-severity vulnerability, CVE-2026-85046, which attackers were already exploiting. The bug affects Chrome's JavaScript engine, but details on its specific impact and the attackers remain undisclosed.

Key Numbers

12security fixes in the update
9high-severity bugs addressed
2medium-severity bugs addressed
$1,000bug bounty awarded

Who's Involved

Google
company that patched the Chrome flaw
CVE-2026-85046
vulnerability being exploited
Salvatore Gulizia
security researcher who reported the flaw
Google Patches Chrome Flaw Exploited by Hackers

↳ Why This Matters

This update is critical for users to protect themselves from ongoing cyberattacks that exploit a known vulnerability in the widely used Chrome browser, safeguarding personal data and preventing potential system compromise.

Key facts

  • Google has patched a high-severity Chrome flaw, CVE-2026-85046, after confirming it was being actively exploited.
  • The vulnerability affects Chrome's V8 JavaScript engine.
  • The patch is included in Chrome versions 152.0.7977.82 and 152.0.7977.83 for Windows and Mac, and 152.0.7977.82 for Linux.
  • The update contains a total of 12 security fixes, including nine high-severity bugs.
  • Google has released a security update for its Chrome browser to address a high-severity vulnerability, identified as CVE-2026-85046, which attackers were actively exploiting. The bug impacts the V8 engine, responsible for running JavaScript and WebAssembly within Chrome. While Google has confirmed the exploit's existence in the wild, the company has not yet disclosed details about the attackers, their targets, or the specific capabilities of the exploit. The patch is being rolled out gradually in Chrome versions 152.0.7977.82 and 152.0.7977.83 for Windows and Mac, and version 152.0.7977.82 for Linux. This update includes a total of 12 security fixes, with nine classified as high-severity and two as medium-severity. The vulnerability was reported by security researcher Salvatore Gulizia, who received a $1,000 bug bounty from Google. Although Google has not linked this specific exploit to cryptocurrency theft, the company noted that browser-based crypto theft has been a target through other means, citing previous incidents involving malicious extensions and malware.

    Frequently asked questions

    CVE-2026-85046 is a type-confusion bug affecting Google Chrome's V8 JavaScript engine, where software incorrectly interprets data types, potentially leading to memory errors or unexpected behavior.

    Yes, Google confirmed that an exploit for CVE-2026-85046 exists in the wild and is being used by attackers.

    Google has released a security update for Chrome that includes a patch for this vulnerability.

    Google has not yet linked this specific exploit to cryptocurrency theft, but browser-based crypto theft is an ongoing concern through other methods.

    What Happens Next

    01Google will continue to roll out the security update over the coming days and weeks.
    02Google may publish more information about the exploit once most users have installed the patch.
    CME Headlines
    • Risk Management and Monitoring Notice: Multi-Factor Authentication Updates - September 12
      3 Sep · 5:00 AM

    How It Developed

    Google confirmed CVE-2026-85046 is being exploited in the wild.
    A security update for Chrome, version 152.0.7977.82 and 152.0.7977.83, was released.
    The update includes 12 security fixes, with nine rated high-severity.
    Google has not yet linked the exploit to cryptocurrency theft.

    Sources

    T1
    Update Your Browser: Google Patches Chrome Flaw Hackers Were Already UsingDecrypt

    Related Stories

    G7 Warns of Quantum Computing Threat, Urges Migration to Post-Quantum Cryptography
    4 Sep · 9:21 PM
    OpenAI to improve disclosure of rogue AI incidents
    5 Sep · 2:57 PM
    Spammers adopt AI attack technique to evade email filters
    4 Sep · 5:26 PM
    Authors Wrangle With Publishers Over $1.5 Billion Anthropic A.I. Settlement
    5 Sep · 9:16 AM
    OpenAI agents discussed bypassing security restrictions on public wiki
    4 Sep · 10:20 PM