Google has patched a high-severity Chrome vulnerability, CVE-2026-85046, after confirming it was exploited in the wild. According to ChainCatcher, the flaw was found in the V8 engine used to run JavaScript and WebAssembly, and Google did not disclose the attacker, target, or exact exploitation method.
The fix is included in Chrome versions 152.7977.82 and 152.7977.83 and will roll out over the next few days or weeks. The vulnerability was reported by security researcher Salvatore Gulizia on August 4, who received a $1,000 bug bounty. The update includes 12 security fixes in total, including nine high-severity issues and two medium-severity issues. Google has not linked the flaw to any crypto asset theft, although browser wallets, exchange accounts, and trading extensions have previously been targeted through other methods.