chrome-zero-day

An emergency update for Google Chrome fixes a vulnerability that has already been exploited in real-world attacks: all it takes is opening a malicious webpage.

Google has released a security update for Chrome that fixes a critical vulnerability, identified as CVE-2026-85046. Unlike many other fixes, this one was already being exploited by attackers at the time of publication—which is why it deserves to be addressed as a priority, rather than put off until “when I have time.”

The problem lies in V8, the engine that runs JavaScript code on web pages. To put it simply: all it takes is for someone at the company to open a webpage rigged by attackers for them to be able to execute code on that computer, without requiring any additional clicks or file downloads. This is exactly the kind of attack that shows no visible signs.

Google has fixed the vulnerability in version 152.0.7977.82 of Chrome for Windows, macOS, and Linux. Older versions remain vulnerable until they are updated.

For a small business, which rarely has a dedicated IT staff member, the real risk isn't the complexity of the attack, but the simple fact that no one checks to see if the browsers are up to date. Just one computer left unupdated is enough.

Here's what to do: Open Chrome, click the three-dot menu in the top-right corner, then select Help and About Google Chrome. The browser will automatically check for an update and download it. Very important: Restart Chrome afterward—the update won't take effect until after the restart. Repeat this check on all the computers at the office and remind your coworkers not to put off restarting.

The basic rule remains simple: browser updates aren't a luxury—they're your first line of defense. An up-to-date browser closes, in five minutes, a backdoor that attackers are actively seeking.

Sources:

This article was generated with AI assistance.

Request a quote

← All news