The CVE-2026-85046 Chrome patch (V8) addresses a critical type-confusion bug in the Chrome browser. Included in the update are versions 152.0.7977.82 and 152.0.7977.83 for Windows, Mac, and Linux, specifically addressing the flaw. Security researcher Salvatore Gulizia, known as Serotav, reported this vulnerability on August 4, and Google has recognized his contribution with a $1,000 bug bounty. Importantly, Google has acknowledged that this vulnerability has been exploited in the wild. The rollout of this update will continue over the coming days and weeks, aiming to protect users across different platforms.
Google’s latest Chrome update includes a total of 12 security fixes, of which the company lists nine as high-severity and two as medium-severity vulnerabilities. The advisory describing the update groups these counts among the package of security corrections and states that several technical specifics of the fixes are being withheld until most users have installed the patches. Google also has not identified any attackers or victims linked to the issues, and it has not described the specific capabilities of the exploit associated with the addressed vulnerability. The company has not provided a date for when it will publish further technical information about the withheld details.
Google has not identified the attackers involved in the exploit tied to CVE-2026-85046, and the company has not disclosed any victims associated with that vulnerability. Google also has not described what the exploit can do or the specific impacts it may have on affected systems. The company has not provided a schedule or date for when it will publish additional technical information or further details about the exploit. Those points were presented in the public advisory without attribution of attackers, identification of victims, or specification of exploit capabilities, and no publication date for more information has been announced.
Multiple browser-related security incidents were reported between November 2025 and August, involving malicious and fake browser extensions as well as malware targeting browser-connected cryptocurrency wallets. In November 2025, researchers found a malicious Chrome extension that added hidden SOL transfers to users’ swaps. In December 2025, a Singapore entrepreneur reported malware disguised as a game that drained more than $14,000 from browser-connected wallets; that report included a belief the incident involved stolen authentication tokens and an earlier Chrome zero-day. In August, researchers uncovered dozens of fake Firefox wallet extensions that stole wallet credentials. No direct link to CVE-2026-85046 has been reported for any of these incidents.
The CVE-2026-85046 Chrome patch (V8) rollout is underway and underscores the ongoing security focus of browser updates across platforms. Recent disclosures and patch releases demonstrate active maintenance and engagement with external researchers through established reporting and reward processes. Keeping browser installations current remains an essential measure for receiving these protections while updates continue to deploy.


