Government Advisory

Actively Exploited Chrome Flaw Added to US Government's Must-Patch List

CISA · 4 Sept 2026
Key Takeaway Restart your Chrome browser regularly to ensure security patches are actually applied, rather than just downloaded and waiting.

The US Cybersecurity and Infrastructure Security Agency (CISA) has added a new vulnerability affecting Google Chrome's V8 engine, CVE-2026-85046, to its Known Exploited Vulnerabilities (KEV) Catalog. This confirms attackers are actively using this flaw, described as a 'type confusion' issue, to compromise systems.

Chrome is one of the world's most widely used browsers, and vulnerabilities like this can allow attackers to run malicious code or take control of a device simply through malicious web content. While CISA's binding directive requiring rapid patching applies only to US federal agencies, the agency explicitly encourages all organisations, including small and medium businesses, to treat KEV-listed vulnerabilities as high priority and patch quickly.

For Australian small businesses, this is a reminder that browser security updates are not optional extras. Chrome and Chromium-based browsers (such as Edge and Brave) automatically push out security fixes, but users need to restart the browser for updates to take effect. Delaying a restart can leave a known, actively exploited weakness open on your systems.

Chrome CISA known exploited vulnerabilities browser security patch management

Summarised by CISO AI from CISA. We link back to every original so you can read it yourself.