Google Patches Sixth Chrome Zero-Day of 2026, Flagged as Risk to Ethereum (ETH) Wallet Users

Google patched actively exploited Chrome zero-day CVE-2026-85046 in V8; CISA set a Sept. 18 federal deadline as Ethereum wallet users face browser risk.

(08:56 PM UTC)
4 min read
AI SummaryAI
  • Google patched Chrome zero-day CVE-2026-85046 in releases 152.0.7977.82 and 152.0.7977.83.
  • CISA added CVE-2026-85046 to its Known Exploited Vulnerabilities catalog on Sept. 4.
  • Federal civilian agencies must patch the Chrome flaw by Sept. 18 under the CISA deadline.
  • Researcher Salvatore Gulizia reported the V8 bug on Aug. 4, earning a $1,000 bounty.
k7rq2fdm

Chrome 152.0.7977.82 Fixes V8 Flaw

Google has shipped an emergency Chrome update for a high-severity vulnerability that attackers were already exploiting before the patch landed. The bug, tracked as CVE-2026-85046, lives in V8 — the engine that executes JavaScript and WebAssembly inside Chrome — and is classified as a type-confusion flaw. That class of bug arises when software treats data as the wrong type, corrupting memory in ways attackers can chain toward arbitrary behavior inside the browser sandbox. In the official Chrome Releases notice published Thursday, the company confirmed an exploit “exists in the wild,” while withholding details of what the exploit can do until most users — and affected third-party projects — have patched. The fix arrives in Chrome 152.0.7977.82 and 152.0.7977.83 for Windows and Mac, and 152.0.7977.82 for Linux, rolling out over the coming days and weeks. The stable-channel update carries 12 security fixes in total, nine rated high-severity and two medium. Google's bounty program paid security researcher Salvatore Gulizia — who reports under the handle Serotav — a $1,000 reward for disclosing the V8 bug on Aug. 4. The company has not identified the attackers, the victims, or which campaigns deployed the exploit, and it has not said when fuller technical detail will be published. Type-confusion bugs in V8 have historically been among the most consequential Chromium flaws precisely because the engine touches every page a user loads. The response has escalated beyond Google's own channel: CISA added CVE-2026-85046 to its Known Exploited Vulnerabilities catalog on Sept. 4, giving US federal civilian agencies until Sept. 18 to patch. For Chrome, this is the sixth zero-day fixed in 2026 — a pace that keeps browser hygiene at the top of the operational-risk list for anyone who signs transactions from a desktop wallet.

Browser Wallets Remain Prime Targets

Google has not connected CVE-2026-85046 to cryptocurrency theft — yet. But the browser is where most self-custody actually happens: Ethereum (ETH) wallet extensions, exchange sessions and portfolio dashboards all run inside the same V8 sandbox this bug sits in. The recent record shows how attackers work that surface through other doors. In November 2025, researchers found a malicious Chrome extension that injected hidden SOL transfers into users' swap flows, skimming funds while the transaction appeared normal. A month later, a Singapore entrepreneur reported that malware disguised as a game drained more than $14,000 from his browser-connected wallets, an attack he attributed to stolen authentication tokens and an earlier Chrome zero-day — though no link to the current CVE has been reported. Last month, researchers uncovered dozens of fake Firefox wallet extensions built purely to harvest credentials. None of these incidents involved CVE-2026-85046 itself, but together they map the attack chain a browser-level memory bug would slot into perfectly: compromise the tab, hijack the session, sign on the victim's behalf. The common thread is misplaced trust in the browser tab, where lures range from counterfeit airdrop claims to extensions posing as tools for new networks, from layer-2 rollups to layer-3 ecosystems, and even dashboards used by market makers. Capital parked in browser wallets — including stablecoins such as USDC issued by Circle — sits one malicious extension away from exposure. For Ethereum (ETH) browser-wallet users in particular, applying this update is not optional hygiene but a prerequisite for signing anything. Readers tracking the market in real time can follow live spot and futures prices on Binance.

Update Before the Next Session

COINOTAG's reading of the primary records is direct: Google's own Chrome Releases notice and CISA's Known Exploited Vulnerabilities catalog — the two authoritative documents in this case — both confirm that exploitation was underway before the patch shipped. The actionable step is simple: open “Help → About Google Chrome,” confirm version 152.0.7977.82 or later, and do it before the next session that touches a wallet or exchange. The deeper trend — six Chrome zero-days patched in 2026 alone — suggests browser-level compromise will remain the cheapest path to self-custody keys, and hardware wallets, where private keys never touch the browser, remain the stronger boundary for meaningful balances.

COINOTAG News Desk

COINOTAG News Desk

COINOTAG's editorial and research desk.

How our News Desk works
AI-Assisted

AI-generated, AI-reviewed, under COINOTAG editorial oversight.