web3 : Google fixes the exploited high-risk vulnerability of Chrome
Coinpaper
9h ago
Ai Focus
Google fixes a high-risk vulnerability in Chrome that has been exploited, with the incident involving security risks for browser wallets and transaction accounts.
Helpful
No.Help

Google has fixed a high-risk vulnerability ( Chrome ) that was confirmed to be exploitable, and has begun to push updates to users of Windows, Mac, and Linux. This vulnerability is located in the V8 engine of Chrome and affects the browser's execution of JavaScript and WebAssembly.

It has been confirmed that there is unauthorized utilization by outsiders.

In a security notice released on Thursday, Google stated that exploit code for CVE-2026-85046 is being used in real environments. However, Google has not yet disclosed the identity of the attackers, the scope of victims, nor has it explained what consequences this vulnerability could ultimately lead to.

  • Windows and Mac: 152.0.7977.82 / 152.0.7977.83
  • Linux : 152.0.7977.82
  • The updates will be rolled out gradually over the next few days to weeks.

The vulnerability is located in the V8 engine.

Google describes this issue as a "type confusion" vulnerability. Such vulnerabilities typically occur when a program incorrectly handles data types, which may lead to memory errors or other abnormal behaviors. Google has not yet clarified whether this vulnerability can be used for remote code execution.

Security researcher Salvatore Gulizia (online username Serotav) reported this issue on August 4th, and Google awarded him a bounty of $1,000 for the vulnerability.

This update fixes a total of 12 issues.

Google indicates that this Chrome update contains a total of 12 security fixes, including 9 high-risk vulnerabilities and 2 medium-risk vulnerabilities. For security reasons, some technical details will not be made public until the majority of users and affected third-party projects have completed their updates.

As of now, Google has not indicated when more information related to this exploitation incident will be disclosed.

There were instances where browser plugins were used to attack encrypted users.

Although Google has not directly linked CVE-2026-85046 to the incident of encrypted assets being stolen, browsers have always been an important entry point for attacks on encrypted users, especially when it comes to wallet plugins, exchange accounts, and trading extension tools.

Public cases have shown that in November 2025, researchers discovered a malicious Chrome extension that secretly added SOL transfer instructions when users exchanged tokens. A month later, a Singaporean entrepreneur claimed that malware disguised as a game stole over $14,000 from the wallet connected to his browser. Additionally, in August of this year, researchers also found dozens of forged Firefox wallet extensions used to steal wallet credentials.

Tip
$0
Like
0
Save
0
Views 39
WalletJYS reminds readers to view blockchain rationally, stay aware of risks, and beware of virtual token issuance and speculation. All content on this site represents market information or related viewpoints only and does not constitute any form of investment advice. If you find sensitive content, please click“Report”,and we will handle it promptly。
Submit
Comment 0
Hot
Latest
No comments yet. Be the first!
Related
Aave V4 Plans to Conduct the 16th Round of Parameter Adjustments: Deposit of Approximately $577 Million, Still Moderate in Scaling Up
On September 4th, LlamaRisk submitted the sixteenth round of parameter adjustment suggestions for Aave to the governance forum. The proposal indicates that after the previous round of adjustments, the total deposits of Aave V4 distributed across two chains and five liquidity centers amounted to approximately 577 million US dollars, of which Global Dollar Hub accounted for about 94 million US dollars and Plus Hub about 21 million US dollars. This round plans to add an additional 7 million US dollars in collateral capacity, mainly focused on Ethereum Plus Hub, and also adjusts multiple borrowing credit lines and interest rate models.
币界网
·2026-09-06 09:57:00
25
EURC connects to CCTP: Circle uses destruction and re-casting to bridge Ethereum with Base
On September 2nd, Circle announced that its cross-chain transfer protocol CCTP has begun to support the native cross-chain transfer of the euro stablecoin EURC. The first networks to support this feature are Ethereum and Base. Developers can use the same production-grade interoperability infrastructure as USDC to move EURC between the two chains. It's important to clarify that this announcement only confirms support between Ethereum and Base; it does not imply that EURC has already covered all blockchains through CCTP.
币界网
·2026-09-06 09:55:41
25
Canada's employment decreased by 42,000 in August: Unemployment rate remains unchanged, but participation rate is declining
The Canadian Statistics Agency released a labor force survey for August on September 4th, which showed that the number of employed people decreased by 42,000 compared to the previous month, a decline of 0.2%; the employment rate fell by 0.1 percentage points to 60.8%, while the unemployment rate remained at 6.4%. On the surface, the unemployment rate has not worsened, but the simultaneous decline in employment and labor participation rates indicates that some of the pressure has been absorbed by people leaving the labor force or temporarily not seeking employment. Therefore, the situation this month cannot be simply summarized as "stable unemployment rate."
币百科
·2026-09-06 09:53:43
13
WeatherNext 3 integrates real-time satellite data: AI Weather forecasts will now be updated hourly
Google DeepMind and Google Research released WeatherNext on September 3rd. Officials stated that this global weather AI model can directly incorporate real-time data from geosynchronous satellites and meteorological station observations to generate new forecasts hourly, and it has improved the spatial resolution of certain surface variables to 5 kilometers. This capability has already been integrated into Google search, Gemini, maps, Google Maps Platform, and Cloud, indicating that the research model is now being utilized in the daily decision-making processes of ordinary users and enterprises.
CoinMeta
·2026-09-06 09:52:24
13
web3 : Solana Attracted $348 million in the past 30 days RWA Net inflow
Solana recorded $348 million in the past 30 days with a net inflow of RWA. The total value on the chain has risen to $4.23 billion, and the number of holders continues to grow.
U.Today
·2026-09-06 09:12:34
17
View More