Google Fixes Exploited Chrome Flaw Amid Ongoing Crypto Theft Concerns
Google has patched a high-severity Chrome flaw that hackers were already exploiting. The bug, known as CVE-2026-85046, is a type-confusion bug that occurs when software treats data as the wrong type, causing memory errors or other unexpected behavior.
The patch includes 12 security fixes, with nine of them being high-severity and two medium-severity. Google has not identified the attackers, their victims, or what the exploit can do.
Security researcher Salvatore Gulizia reported the flaw on August 4, and Google awarded him a $1,000 bug bounty. The patch is included in Chrome version 152.0.7977.82 and 152.0.7977.83 for Windows and Mac, and version 152.0.7977.82 for Linux.
Google has not said when it will publish more information about the exploit or whether it can be used to run code remotely. However, browser-based crypto theft remains a concern, as researchers have found that malicious Chrome extensions and malware disguised as games have targeted browser-connected wallets in recent months.