Technology 19 sources · over 3 days Latest coverage 5 Sept 2026, 7:49 am UTC

Google Rushes Chrome Updates to Patch Actively Exploited Security Flaws

Google has released urgent updates for Chrome to fix multiple vulnerabilities, including a zero-day flaw already being exploited by attackers, prompting immediate action for browser users worldwide.

By Samuel Adeyemi · First published 5 Sept 2026

In brief

  1. Google patched 26 security vulnerabilities in Chrome on September 2, including two critical use-after-free bugs.
  2. A new emergency update on September 4 addressed 12 additional flaws, with at least one actively exploited zero-day vulnerability.
  3. The most severe flaw, CVE-2026-85046, affects Chrome's V8 JavaScript engine and can allow attackers to execute arbitrary code.
  4. Security agencies have added the exploited vulnerability to official advisories, urging users to update Chrome without delay.
  5. This marks the sixth zero-day vulnerability in Chrome patched by Google in 2026, highlighting ongoing threats to browser security.
Google Rushes Chrome Updates to Patch Actively Exploited Security Flaws
Source: Cyber Security News

Timeline · 6 moments

6 moments Open the full timeline →

Google patches 26 vulnerabilities in Chrome, including two critical flaws

Cyber Security News ↗

Security agencies warn vulnerabilities could allow arbitrary code execution

Center for Internet Security - Multi-State Information Sharing and Analysis Center ↗

Google issues emergency update for actively exploited zero-day flaw

Cyber Security News ↗

Security update fixes 12 vulnerabilities, including exploited V8 engine bug

Talkback.sh - All ↗

US CISA adds Chrome V8 flaw to Known Exploited Vulnerabilities catalog

Security Affairs ↗

Experts urge Chrome users to update immediately to stay protected

DEV Community ↗

How it started

Google's Chrome browser has long been a target for cyber attackers due to its widespread use. Security researchers and Google's own teams regularly discover vulnerabilities in the browser's code, particularly in complex components like the V8 JavaScript engine.

In early September 2026, Google identified a cluster of security flaws, including some that could allow attackers to take control of affected systems. These vulnerabilities were significant enough to prompt quick action from Google's security team.

How it unfolded

On September 2, 2026, Google released updates for Chrome version 152.0.7977.75/.76 for Windows and macOS, and 152.0.7977.75 for Linux, patching 26 vulnerabilities. Two of these were critical use-after-free flaws, which can let attackers run arbitrary code if exploited, a risk flagged by security advisories.

Days later, on September 4, Google issued another emergency update after discovering that some vulnerabilities were being exploited in real-world attacks. Among the 12 flaws patched, CVE-2026-85046 stood out as a high-severity zero-day vulnerability affecting the V8 JavaScript and WebAssembly engine. This flaw allows attackers to execute code on victims' machines simply by getting them to visit a malicious website.

The company confirmed that this vulnerability was already being used in active attacks. Security organizations and government agencies, such as the U.S. Cybersecurity and Infrastructure Security Agency (CISA), quickly added the flaw to their lists of known exploited vulnerabilities. Experts and news outlets urged users to update Chrome immediately to protect against these threats.

This latest incident marked the sixth zero-day vulnerability in Chrome to be patched in 2026, reflecting persistent targeting of the browser by hackers.

Where it stands

Google's emergency updates are now available for all major desktop platforms. Users are encouraged to update their browsers as soon as possible, as attackers are actively exploiting at least one of the patched flaws.

Security advisories stress that failing to update leaves users vulnerable to attacks that could result in stolen data or compromised devices. The patched vulnerabilities are now widely documented, and the risk of exploitation remains high for unpatched systems.

What to watch

Security experts are monitoring for further attacks that may take advantage of these or similar browser vulnerabilities. Google is expected to continue releasing updates as new issues are found, and users should remain vigilant about applying browser patches promptly.

There may also be further disclosures about the methods attackers used to exploit these vulnerabilities, which could help improve browser security in the future.

Written from 19 outlets' coverage of this story. Every timeline entry links to the original report.

More in Technology

All →