web3 : Google fixes the exploited high-risk vulnerability of Chrome
Coinpaper
1h ago
Ai Focus
Google fixes a high-risk vulnerability in Chrome that has been exploited, with the incident involving security risks for browser wallets and transaction accounts.
Helpful
No.Help

Google has fixed a high-risk vulnerability ( Chrome ) that was confirmed to be exploitable, and has begun to push updates to users of Windows, Mac, and Linux. This vulnerability is located in the V8 engine of Chrome and affects the browser's execution of JavaScript and WebAssembly.

It has been confirmed that there is unauthorized utilization by outsiders.

In a security notice released on Thursday, Google stated that exploit code for CVE-2026-85046 is being used in real environments. However, Google has not yet disclosed the identity of the attackers, the scope of victims, nor has it explained what consequences this vulnerability could ultimately lead to.

  • Windows and Mac: 152.0.7977.82 / 152.0.7977.83
  • Linux : 152.0.7977.82
  • The updates will be rolled out gradually over the next few days to weeks.

The vulnerability is located in the V8 engine.

Google describes this issue as a "type confusion" vulnerability. Such vulnerabilities typically occur when a program incorrectly handles data types, which may lead to memory errors or other abnormal behaviors. Google has not yet clarified whether this vulnerability can be used for remote code execution.

Security researcher Salvatore Gulizia (online username Serotav) reported this issue on August 4th, and Google awarded him a bounty of $1,000 for the vulnerability.

This update fixes a total of 12 issues.

Google indicates that this Chrome update contains a total of 12 security fixes, including 9 high-risk vulnerabilities and 2 medium-risk vulnerabilities. For security reasons, some technical details will not be made public until the majority of users and affected third-party projects have completed their updates.

As of now, Google has not indicated when more information related to this exploitation incident will be disclosed.

There were instances where browser plugins were used to attack encrypted users.

Although Google has not directly linked CVE-2026-85046 to the incident of encrypted assets being stolen, browsers have always been an important entry point for attacks on encrypted users, especially when it comes to wallet plugins, exchange accounts, and trading extension tools.

Public cases have shown that in November 2025, researchers discovered a malicious Chrome extension that secretly added SOL transfer instructions when users exchanged tokens. A month later, a Singaporean entrepreneur claimed that malware disguised as a game stole over $14,000 from the wallet connected to his browser. Additionally, in August of this year, researchers also found dozens of forged Firefox wallet extensions used to steal wallet credentials.

Tip
$0
Like
0
Save
0
Views 15
CoinMeta reminds readers to view blockchain rationally, stay aware of risks, and beware of virtual token issuance and speculation. All content on this site represents market information or related viewpoints only and does not constitute any form of investment advice. If you find sensitive content, please click“Report”,and we will handle it promptly。
Submit
Comment 0
Hot
Latest
No comments yet. Be the first!
Related
OpenAI Confirming German Wiki Agent Events
OpenAI Confirms German Wiki Agent Events, and States That They Are Studying More Clear AI Accident Disclosure Standards.
TechCrunch
·2026-09-06 02:14:00
8
web3: ZEC breaks through $1,000, Ironwood migration boosts market attention
ZEC breaks through $1,000, Zcash completes large-scale supply migration after the hard fork in July, and the pool size of Ironwood rises to 3.86 million coins.
CoinPedia
·2026-09-06 02:13:57
10
web3: Foreign media: The bottleneck in AI infrastructure is shifting towards electricity
Foreign media reports that the expansion of the AI data center is placing electricity in a more critical position than that of GPU; utilities, microgrids, and mining power assets are coming under attention.
Coinpaper
·2026-09-06 01:52:23
17
web3 : XRP Spot trading volume reaches a six-month high, but buying orders remain to be confirmed
XRP achieved a half-year high in spot trading volume in August, but CVD remains negative, and the strength of buying orders still needs further confirmation.
CoinPedia
·2026-09-06 01:09:26
21
web3: Multiple ancient Bitcoin wallets awakened, with approximately $15.73 million transferred out
Four long-dormant Bitcoin wallets recently transferred out 202.84 BTC, with one of the transactions going to Coinbase, sparking market attention to the return of old coins.
Coinpaper
·2026-09-06 01:09:25
22
View More