In summary: On September 3, Google released a patch for a Chrome vulnerability—CVE-2026-85046—that attackers were already exploiting. The vulnerability is triggered when a user opens a compromised web page. For an SME, the key is not to panic, but to determine how many days it will actually take for the organization’s browser fleet to update.
What Happened
On September 3, 2026, Google released the stable version 152.0.7977.82 of Chrome (152.0.7977.83 on macOS), which fixes twelve vulnerabilities. One of them, CVE-2026-85046, was already being exploited in real-world attacks at the time the patch was released.
This is a type confusion vulnerability in V8, the browser's JavaScript and WebAssembly engine. The browser manipulates a memory region believing it contains an object of one type, when in fact it contains another. An attacker who controls the displayed content can exploit this behavior to execute their own code. The CVSS score assigned is 8.8. The vulnerability was reported to Google in early August by an external researcher, Salvatore Gulizia.
On September 4, the U.S. agency CISA added the vulnerability to its list of actively exploited flaws and set September 18 as the patch deadline for U.S. federal agencies. This is the sixth zero-day vulnerability patched in Chrome since the beginning of the year.
Does this apply to me?
Most likely, at least in part. Chrome isn't the only one affected: Edge, Brave, Opera, and Vivaldi are all based on the same Chromium platform and are vulnerable to the flaw until their developers implement Google's fix. In a Microsoft environment, Edge is often the default browser, including for components that display web content without anyone intentionally opening a browser.
A few situations warrant special attention:
- computers that are left on all the time, where the browser hasn't been closed for weeks;
- devices outside the domain or personal devices used to access your business tools;
- servers and virtualized environments on which a browser remains installed;
- positions in the workshop, in production, or in self-service, which are rarely monitored by IT.
To see where you stand, an inventory remains the fastest way. Your fleet management tool—or Intune, if you're in a Microsoft environment—reports the installed version for each workstation. Without such a tool, opening chrome://settings/help on a sample machine provides an indication, but no guarantee for the rest of the fleet.
What to Do Now
A note before taking action: not all vulnerabilities require the same response. In most cases, three criteria are enough to make a decision. Is the vulnerability being exploited in the wild? Is the product exposed—that is, affected by content coming from the internet? Is a patch available? In this case, the answer to all three questions is yes, which places this issue in the “address this week” category rather than “wait until the next cycle.” We explain this triage process in detail in our analysis of August’s Patch Tuesday.
1. Restart your browsers. Chrome and Edge download their updates in the background, but the fix isn’t applied until the browser is completely closed. On a computer left on with forty tabs open, the update will wait indefinitely. A message to the team is often all it takes: this week, we’ll close the browser at the end of the day.
2. Check the actual coverage rather than the assumed coverage. Pull up the list of installed versions and look at the tail, not the average. It’s the ten overlooked workstations that cause problems, not the 190 that update on their own. If Edge is your corporate browser, also check that the update channel hasn’t been locked to an older version for application compatibility reasons.
3. Handle exceptions and document them somewhere. Almost every small and medium-sized business has at least one system that cannot be updated: production machinery, legacy business software, or end-of-life hardware. This isn’t a problem as long as the system is identified and its web browsing is restricted. The real risk is the exception that no one has documented.
Not sure about your exposure?
Get an update from an IT Systems expert
A quick assessment of your exposure and the steps you should take. No obligation.
In a nutshell
A Chrome vulnerability was exploited even before its patch—released on September 3—was applied; it was fixed in version 152.0.7977.82. The key step can be summed up in one sentence: make sure all browsers on your network have been restarted, including Edge. This isn't a ransomware-level emergency, but it's the kind of task that drags on for months if no one takes care of it.
If your fleet is tracked and inventoried, you're probably already covered without even realizing it. If not, this is a good excuse to update your inventory.
Frequently asked questions
Does Chrome update automatically? The download happens automatically, but the patch isn't applied until the browser is completely closed. If you see an update banner in Chrome, it means the browser hasn't been restarted yet.
Should you uninstall Chrome and switch to Edge? No. Edge is based on the same engine and is susceptible to the same type of vulnerability. The choice of browser depends on other factors, not this one.
Does antivirus software protect against this type of vulnerability? Partially. An EDR solution can detect the behavior that follows the exploit, but it does not replace the patch, which removes the root cause.
— Samir Amara, CEO — IT Systèmes

.jpg)




.jpeg)