Threat Intelligence

Google Patches Actively Exploited Chrome Zero-Day: Update Now

The Hacker News · 4 Sept 2026
Key Takeaway Update Chrome on all business devices immediately, and consider enabling automatic browser updates to stay protected against actively exploited vulnerabilities.

Google has issued a security update for Chrome to fix 12 vulnerabilities, including one that hackers are already using in real-world attacks. The flaw, tracked as CVE-2026-85046, is a high-severity "type confusion" bug in V8, the engine that powers Chrome's JavaScript and WebAssembly processing. Google confirmed the issue affects Chrome versions prior to 152.0.7977.82.

Type confusion vulnerabilities occur when software incorrectly handles data types, which can allow an attacker to corrupt memory and potentially run malicious code on a victim's device. Because this particular bug is being actively exploited, businesses using Chrome are at real risk if they delay updating. Google has not shared full technical details of the exploit to prevent further abuse while users update their browsers.

For small businesses, browser vulnerabilities like this are especially concerning because Chrome is widely used for everyday work, from email to cloud applications. Attackers exploiting these flaws can gain unauthorised access to systems without any obvious warning signs, making rapid patching essential.

Summarised by CISO AI from The Hacker News. We link back to every original so you can read it yourself.