We use cookies on this website.

By clicking "Accept," you agree to the storage of cookies on your device to improve your browsing experience, analyze site usage, and contribute to our marketing efforts. See our privacy policy for more information.

Cybersecurity

Chrome Vulnerability CVE-2026-85046: Should Small and Medium-Sized Businesses Patch It Immediately?

On September 3, Google patched a vulnerability—identified as CVE-2026-85046—that had already been exploited in Chrome’s V8 engine. A malicious web page is all it takes to execute code on the user’s device. Since Edge, Brave, and Opera are all based on the same Chromium framework, the issue of update timelines is a concern for all small and medium-sized businesses.

Chrome Vulnerability CVE-2026-85046: Should Small and Medium-Sized Businesses Patch It Immediately?

In summary: On September 3, Google released a patch for a Chrome vulnerability—CVE-2026-85046—that attackers were already exploiting. The vulnerability is triggered when a user opens a compromised web page. For an SME, the key is not to panic, but to determine how many days it will actually take for the organization’s browser fleet to update.

What Happened

On September 3, 2026, Google released the stable version 152.0.7977.82 of Chrome (152.0.7977.83 on macOS), which fixes twelve vulnerabilities. One of them, CVE-2026-85046, was already being exploited in real-world attacks at the time the patch was released.

This is a type confusion vulnerability in V8, the browser's JavaScript and WebAssembly engine. The browser manipulates a memory region believing it contains an object of one type, when in fact it contains another. An attacker who controls the displayed content can exploit this behavior to execute their own code. The CVSS score assigned is 8.8. The vulnerability was reported to Google in early August by an external researcher, Salvatore Gulizia.

On September 4, the U.S. agency CISA added the vulnerability to its list of actively exploited flaws and set September 18 as the patch deadline for U.S. federal agencies. This is the sixth zero-day vulnerability patched in Chrome since the beginning of the year.

Does this apply to me?

Most likely, at least in part. Chrome isn't the only one affected: Edge, Brave, Opera, and Vivaldi are all based on the same Chromium platform and are vulnerable to the flaw until their developers implement Google's fix. In a Microsoft environment, Edge is often the default browser, including for components that display web content without anyone intentionally opening a browser.

A few situations warrant special attention:

  • computers that are left on all the time, where the browser hasn't been closed for weeks;
  • devices outside the domain or personal devices used to access your business tools;
  • servers and virtualized environments on which a browser remains installed;
  • positions in the workshop, in production, or in self-service, which are rarely monitored by IT.

To see where you stand, an inventory remains the fastest way. Your fleet management tool—or Intune, if you're in a Microsoft environment—reports the installed version for each workstation. Without such a tool, opening chrome://settings/help on a sample machine provides an indication, but no guarantee for the rest of the fleet.

What to Do Now

A note before taking action: not all vulnerabilities require the same response. In most cases, three criteria are enough to make a decision. Is the vulnerability being exploited in the wild? Is the product exposed—that is, affected by content coming from the internet? Is a patch available? In this case, the answer to all three questions is yes, which places this issue in the “address this week” category rather than “wait until the next cycle.” We explain this triage process in detail in our analysis of August’s Patch Tuesday.

1. Restart your browsers. Chrome and Edge download their updates in the background, but the fix isn’t applied until the browser is completely closed. On a computer left on with forty tabs open, the update will wait indefinitely. A message to the team is often all it takes: this week, we’ll close the browser at the end of the day.

2. Check the actual coverage rather than the assumed coverage. Pull up the list of installed versions and look at the tail, not the average. It’s the ten overlooked workstations that cause problems, not the 190 that update on their own. If Edge is your corporate browser, also check that the update channel hasn’t been locked to an older version for application compatibility reasons.

3. Handle exceptions and document them somewhere. Almost every small and medium-sized business has at least one system that cannot be updated: production machinery, legacy business software, or end-of-life hardware. This isn’t a problem as long as the system is identified and its web browsing is restricted. The real risk is the exception that no one has documented.

Not sure about your exposure?

Get an update from an IT Systems expert

A quick assessment of your exposure and the steps you should take. No obligation.

Request an exchange

In a nutshell

A Chrome vulnerability was exploited even before its patch—released on September 3—was applied; it was fixed in version 152.0.7977.82. The key step can be summed up in one sentence: make sure all browsers on your network have been restarted, including Edge. This isn't a ransomware-level emergency, but it's the kind of task that drags on for months if no one takes care of it.

If your fleet is tracked and inventoried, you're probably already covered without even realizing it. If not, this is a good excuse to update your inventory.

Frequently asked questions

Does Chrome update automatically? The download happens automatically, but the patch isn't applied until the browser is completely closed. If you see an update banner in Chrome, it means the browser hasn't been restarted yet.

Should you uninstall Chrome and switch to Edge? No. Edge is based on the same engine and is susceptible to the same type of vulnerability. The choice of browser depends on other factors, not this one.

Does antivirus software protect against this type of vulnerability? Partially. An EDR solution can detect the behavior that follows the exploit, but it does not replace the patch, which removes the root cause.

— Samir Amara, CEO — IT Systèmes

Our latest articles

See more
Cybersecurity

Safety Maintenance (MCS): Definition and Method

Security Maintenance (MCS) ensures a system remains secure over time: definition, differences from MCO, ANSSI and NIS2 requirements, and methodology.
September 7, 2026
Custom Software Development Providers for Small and Medium-Sized Businesses and Mid-Size Companies
Development & automation

Top Custom Software Development Providers for Small and Medium-Sized Businesses in France in 2026

Which company can develop your custom business software? A comparison of four French service providers based on market positioning, starting price, and turnaround time, for small and medium-sized businesses.
September 7, 2026
Cybersecurity

PaperCut Vulnerability Exploited (CVE-2026-82078): Is Your Print Server Affected?

On August 27, 2026, PaperCut released an emergency patch for two vulnerabilities in its NG and MF print servers, which had already been exploited by attackers. CERT-FR relayed the alert and updated it on August 31 with new indicators. Here’s how to find out in just a few minutes if your company is affected—and what to do in the hours that follow.
September 3, 2026
Cybersecurity

Hello, E.Leclerc: The leak came from a service provider—here’s what an SME should check with its own staff

LCommerce, the company that operates the Allo E.Leclerc service, has informed some of its customers that one of its external logistics providers had been hacked. Names, email addresses, and phone numbers were compromised, but no banking information was exposed. The incident was reported to the CNIL and serves as a reminder that a company can be affected even if its own system has not been compromised.
September 1, 2026
Helpy Barometer: Resolution rate for Level 1 tickets measured on the IT Systèmes internal help desk
MSP & Managed IT Services: Proactive IT Management for Small and Medium-Sized Businesses

Helpy 2026 Barometer: 44% of Level 1 tickets resolved without human intervention

44% of Level 1 tickets were resolved without human intervention, with an average resolution time of 3 minutes. Eleven months of data collected from our own help desk, including methodology and limitations.
September 4, 2026
IT Security Governance and Steering Meeting in an Open-Plan Office
Cybersecurity

Cybersecurity GRC: Governance, Risk, and Compliance—A Guide for Small and Medium-Sized Businesses

GRC (Governance, Risk, and Compliance) provides a framework for managing IT security. Definition, clarification of differences from CRM, pillars, relationship with NIS2, and implementation for small and medium-sized businesses and mid-sized companies.
August 27, 2026