Google patched two security flaws in Chrome within days of each other in early September, and in both cases it said attackers were already using them. Both bugs sat in V8, the engine that runs JavaScript on every web page, and both could let a booby-trapped page run code inside the browser. If your browser has not restarted since early September, it may not have installed the fixes yet.
What happened
The first flaw, CVE-2026-85046, is a type confusion bug in V8 rated 8.8 out of 10 for severity. BleepingComputer reported on 4 September that Google had released Chrome 152.0.7977.82/.83 for Windows and Mac and 152.0.7977.82 for Linux to fix it, along with 11 other high-severity bugs. The Hacker News reported that the bug was found by researcher Salvatore Gulizia on 4 August and that Google confirmed an exploit exists in the wild but withheld details to protect users who have not updated.
The second, CVE-2026-87491, is an out-of-bounds write in V8. It was fixed in the Chrome 153.0.8010.36/.37 stable release on 8 September. The US Cybersecurity and Infrastructure Security Agency (CISA) added it to its Known Exploited Vulnerabilities catalog on 9 September, which it does only when there is evidence of active exploitation. According to The Hacker News, it was reported by Jihyeon Jeong of Seoul National University's Compsec Lab and is the seventh actively exploited Chrome zero-day disclosed since January 2026.
Google has not said who was exploiting either flaw or who was targeted. That is normal for Chrome zero-days: the company keeps bug details restricted until most users have updated.
Why it matters if you are not a target
A "zero-day" is a flaw attackers find and use before the vendor has a fix. Once the patch ships, the clock runs the other way: the fix itself shows attackers roughly where the bug is, and every browser that has not updated becomes an easier target. Exploits that start in targeted attacks often spread to wider use.
Both flaws were triggered by "a crafted HTML page", in other words by visiting a web page. No download or click on an attachment was needed. That is why browser updates matter more than almost any other update on a computer: the browser is the program that handles untrusted content from strangers all day.
There are two partial safeguards. Both bugs allowed code to run inside Chrome's sandbox, which limits what an attacker can reach without a second flaw to break out. And Chrome updates itself. But Chrome only applies an update when it restarts, so a browser left open for weeks can be running old code even though the update has downloaded.
Other Chromium browsers are affected too
V8 is shared by every browser built on Chromium. CISA's catalog entry notes the flaw could affect browsers that use Chromium, including Microsoft Edge and Opera. Hong Kong's computer emergency response team, HKCERT, said on 16 September that Edge versions before 153.0.4234.32 were affected and that CVE-2026-87491 was being exploited in the wild. Brave, Vivaldi and Opera users should check for updates as well.
What to do
- Chrome on a computer: open the menu, go to Help, then About Google Chrome. Google's help page says Chrome checks for updates on that page; if one is waiting, click Relaunch. Your tabs reopen, but Incognito windows do not.
- Check the version number. On that same page, Chrome should show 153.0.8010.36 or later. Google promoted later versions to stable since then, so a higher number is fine.
- Microsoft Edge: open Settings, then About Microsoft Edge. Edge checks and installs updates there. HKCERT lists 153.0.4234.32 as the fixed version.
- Phones and tablets: update Chrome from Google Play or the App Store. On Android, also install any pending system updates, which include the Android System WebView used by many apps.
- Restart the browser regularly. If you keep dozens of tabs open for weeks, a weekly restart is the simplest way to make sure updates actually apply.
- Keep automatic updates on for your operating system and browser. They are the main defence here; no extension or setting replaces them.
Where security software fits
Antivirus software is not a substitute for patching. A browser exploit runs inside a program you trust, which is exactly what makes it hard for any scanner to spot. What a security suite can add is a second layer: web protection that blocks known malicious sites, and detection of malware if an attacker does manage to drop something on the machine after the browser is compromised. Microsoft Defender, built into Windows, provides that baseline, and paid suites add extra web filtering and features. The order of priority does not change: update first, then protect.
For business owners, the same advice applies with one addition. If staff use Chrome or Edge on company machines, check that browser updates are not blocked by policy, and that the machines actually restart. A managed browser that has downloaded a fix and is waiting for a relaunch is still unpatched.