XRP $3.12 ▲ 4.8% BTC $114,820 ▲ 1.2% ETH $4,380 ▼ 0.6% RLUSD $1.00 ▲ 0.0% XLM $0.41 ▲ 3.1% Fear & Greed 68 · GreedXRP $3.12 ▲ 4.8% BTC $114,820 ▲ 1.2% ETH $4,380 ▼ 0.6% RLUSD $1.00 ▲ 0.0% XLM $0.41 ▲ 3.1% Fear & Greed 68 · Greed
Home / Learn
● Learn

Google Rushes Chrome Security Fix After Discovering Hackers Exploiting V8 Engine Flaw

Google patched CVE-2026-85046, a high-severity vulnerability in Chrome's V8 engine that attackers were already leveraging. The critical update addresses 12 security flaws as browser-based threats to crypto holders continue escalating.

JM
by Jacob Marquez · Learn Desk
Published September 6, 2026 · 2 min read

Active Exploit Discovered in Chrome’s JavaScript Engine

Google confirmed Thursday that attackers were actively exploiting a critical security vulnerability in Chrome before the company could deploy a fix. According to Google’s security notice, as reported by Decrypt, CVE-2026-85046 represents an ongoing threat targeting the browser’s V8 engine, which executes JavaScript and WebAssembly code. The flaw is a type-confusion bug, a class of vulnerability where software mishandles data types, leading to memory corruption and unpredictable system behavior.

The patch released across Chrome 152.0.7977.82 and 152.0.7977.83 for Windows and Mac, and version 152.0.7977.82 for Linux. The rollout will progress over the coming weeks as Google prioritizes reaching all users and third-party developers. The comprehensive security update resolves 12 vulnerabilities total, including nine rated high-severity and two medium-severity, though Google is withholding technical specifics until adoption reaches broader coverage.

Recognition and Disclosure Timeline

Security researcher Salvatore Gulizia, operating under the moniker Serotav, identified and reported the vulnerability on August 4, receiving a $1,000 bug bounty from Google’s researcher recognition program. Notably, Google has declined to disclose the attackers’ identities, their intended targets, or the full scope of what the exploit enables, details that typically surface only after patches achieve widespread deployment.

Growing Threats to Cryptocurrency Users

While Google has not connected CVE-2026-85046 to cryptocurrency-specific attacks, the disclosure arrives amid an expanding wave of browser-based threats targeting digital asset holders. In November 2025, researchers identified a malicious Chrome extension that surreptitiously inserted SOL token transfers into users’ blockchain transactions. December brought reports of malware masquerading as a gaming application that stole over $14,000 from a Singapore entrepreneur’s browser-connected wallets, with suspected links to stolen authentication credentials and a prior Chrome zero-day vulnerability. Most recently, investigators uncovered numerous fraudulent Firefox wallet extensions engineered to harvest wallet credentials directly.

These incidents demonstrate the ongoing vulnerability of browser-based digital asset management. Users holding meaningful cryptocurrency reserves should treat browser security as a critical component of their overall asset protection strategy, prioritizing immediate updates and considering hardware wallets for substantial holdings.

Source: Google, via Decrypt. Not financial advice.

// DISCLAIMER: This article is for informational purposes only and is not financial, investment, or trading advice. Terminalcraft may earn a commission from affiliate links. Crypto is volatile and high-risk. Always do your own research.
JM

Jacob Marquez — Learn Desk

Jacob Marquez is the founder and editor of Terminalcraft, an independent XRP-first crypto news desk. An XRP holder and market watcher since 2016, he started Terminalcraft to deliver fast, factual crypto news without the hype.