Google shipped an emergency Chrome update on 3 September for a zero-day flaw, tracked as CVE-2026-85046, that attackers are already using in real attacks. The bug sits in V8, the engine that runs the JavaScript behind almost every website Chrome opens, and it's a "type confusion" error — a class of bug where the browser mishandles what kind of data it's looking at, which can be twisted into corrupting the browser's memory. Google says it is aware that "an exploit for CVE-2026-85046 exists in the wild" and has, as usual for an active zero-day, withheld technical details to slow down copycat attackers while the patch rolls out. The flaw was responsibly reported by researcher Salvatore Gulizia and carries a CVSS severity score of 8.8.
This is the sixth actively exploited Chrome zero-day Google has patched in 2026 alone — a reminder that the browser, not email or the office server, is often the first thing attackers target, simply because everyone has one open all day. The fix lands in Chrome 152.0.7977.82/.83 (Windows/macOS) and 152.0.7977.82 (Linux), and Chromium-based browsers such as Edge, Brave, Opera and Vivaldi will need their own separate updates once their vendors catch up.
What this means for your business
Chrome updates itself automatically in the background, so most staff are already protected — but only once the browser is actually relaunched. A laptop that's been asleep or left open with the same tabs for days can sit on the vulnerable version indefinitely, since the update downloads quietly but doesn't apply until Chrome restarts. This week is a reasonable moment to have your team close and reopen Chrome, or check Settings > About Chrome to confirm the version is 152.0.7977.82 or later. If anyone on your team uses Edge, Brave, or another Chromium-based browser day to day, check those too — they share the same underlying engine and don't inherit Chrome's fix automatically. If your business manages devices centrally through an MDM or fleet policy, it's worth confirming the update has actually reached every managed machine rather than assuming auto-update covered it everywhere.