Chrome Users Warned: Update Browser Now Amid Active Hack Exploitation
Google has confirmed that attackers were exploiting a security flaw in its Chrome browser before a fix was available. The vulnerability, tracked as CVE-2026-85046, is a type confusion flaw in V8, Chrome's JavaScript and WebAssembly engine. According to Google's advisory, an exploit was in active use before the patch shipped.
The affected vulnerability could allow remote attackers to execute arbitrary code inside the browser's security sandbox by directing users to maliciously constructed webpages. The flaw was reported by security researcher Salvatore Gulizia, also known as 'Serotav', who received a $1,000 bug bounty reward.
Google has withheld further technical details to give users and projects that depend on Chrome time to apply the fix before attackers develop additional methods. The patched release is Chrome 152.0.7977.82/83 for Windows and macOS, and version 152.0.7977.82 for Linux.