Google issues emergency Chrome update after exploited zero-day vulnerability discovered
Google has released an emergency security update for its Chrome browser after researchers identified a serious zero-day vulnerability that is reportedly already being exploited by attackers.
The flaw, identified as CVE-2026-85046, affects Chrome versions running on Windows, macOS and Linux. Google has not disclosed detailed technical information about the vulnerability, allowing users time to install the security fix before more information becomes publicly available.
The company acknowledged that an exploit for the vulnerability is already in circulation. Google said access to technical details and links related to the flaw could remain restricted until a large majority of users have installed the update.
A zero-day vulnerability is particularly concerning because it involves a security weakness that developers have had little or no time to address before it is exploited. Such flaws can therefore expose users to attacks before protective measures are widely available.
According to the information released about the vulnerability, attackers could potentially exploit it by persuading a user to visit a specially crafted HTML page containing malicious code. A successful attack could allow an intruder to take control of an affected browser tab, execute malicious code, disrupt systems or gain access to sensitive information.
Google has not revealed who is behind the attacks, how many users may have been affected or which organizations or individuals have been targeted. The limited disclosure is part of the company’s effort to reduce the risk of further exploitation while the update is being deployed.
The latest incident adds to growing concerns over the increasing sophistication of cyberattacks targeting widely used software. Chrome is one of the world’s most widely used web browsers, meaning that security vulnerabilities can potentially expose a large number of users to malicious activity.
Earlier this year, Google’s threat intelligence researchers also reported what they described as the first evidence of a threat actor using artificial intelligence to develop a zero-day exploit. The researchers said the exploit appeared to have been prepared for a potentially large-scale operation, although its early discovery may have prevented wider use.
Google is urging Chrome users to install the latest security update as soon as possible. Users can check for updates by opening Chrome, going to Settings, selecting About Chrome, and installing any available update before restarting the browser.
The incident once again highlights the importance of keeping browsers and other frequently used software up to date, particularly when security vulnerabilities are known to have been actively exploited.
-
13:21
-
13:19
-
13:05
-
12:45
-
12:30
-
12:12
-
11:47
-
11:35
-
11:31
-
11:19
-
11:15
-
11:10
-
11:08
-
11:00
-
10:56
-
10:56
-
10:55
-
10:55
-
10:41
-
10:25
-
10:10
-
09:47
-
09:32
-
09:15
-
09:00
-
08:42
-
08:21
-
08:05
-
07:45
-
07:30
-
07:15
-
21:36
-
21:30
-
21:25
-
21:22
-
21:15
-
20:50
-
20:37
-
20:27
-
19:00
-
18:40
-
18:18
-
17:47
-
17:30
-
17:10
-
17:07
-
16:47
-
16:32
-
16:16
-
16:00
-
15:59
-
15:52
-
15:49
-
15:44
-
15:25
-
15:10
-
15:04
-
14:48
-
14:33
-
14:25
-
14:18
-
14:15
-
14:14
-
14:04
-
14:00
-
13:42