:

GOOGLE PATCHES CHROME ZERO-DAY ACTIVELY EXPLOITED

SECURITY DESK2 MIN READ
FRI, SEP 4, 2026

■ AI-SUMMARIZED FROM 1 SOURCE ▸ TIMELINE

Google has released an emergency update for Chrome to fix a high-severity zero-day vulnerability in the V8 engine currently being exploited in attacks. The update addresses this flaw plus 11 additional vulnerabilities.

Google addressed the zero-day flaw in Chrome's V8 JavaScript engine, which powers the browser's performance. The vulnerability is classified as high-severity and has been confirmed under active exploitation. The company provided limited technical details about the flaw, a standard practice when vulnerabilities are actively being weaponized. Releasing full specifics could enable additional attackers to develop exploits before users patch their systems. Beyond the zero-day, the update resolves 11 other security issues across varying severity levels. Google's security team regularly identifies and patches flaws through its bug bounty program and internal testing processes. Users should apply the update immediately through Chrome's automatic update feature. The browser typically downloads updates in the background and applies them when restarted. To force an update, users can check Settings > About Chrome, which will prompt the browser to check for available patches. This marks another incident in a recurring pattern of zero-day vulnerabilities affecting major browsers and software platforms. Chrome, while historically one of the more actively patched browsers, continues to face security challenges as attackers target its wide user base and complex codebase. Google's V8 engine is not exclusive to Chrome—it powers Node.js and other applications, though today's vulnerability appears specific to the browser implementation. Organizations managing large Chrome deployments should prioritize this update across their infrastructure. Enterprise administrators can enforce updates through group policy or mobile device management tools rather than relying on individual user actions. No details on the attack scope or affected user count have been disclosed. Google typically provides post-incident analysis once threats are sufficiently mitigated and patches achieve widespread adoption.

■ SOURCES

Bleeping Computer

■ SUMMARY WRITTEN BY AI FROM THE LINKS ABOVE

■ MORE FROM THE SECURITY DESK

A researcher known as Nightmare Eclipse has disclosed a CrowdStrike Falcon zero-day exploit called FalconFlank that enables privilege escalation on fully patched Windows systems. The vulnerability affects the widely-deployed endpoint protection software.

1H AGOSecurity Desk

The U.S. military has disabled ad tracking on service members' devices after foreign adversaries exploited location data to target troops. A senator's letter confirms the action was taken in response to security threats.

1H AGOIndustry Desk

Hewlett Packard Enterprise has released a patch for a critical remote code execution vulnerability in ArubaOS-CX, its network operating system used in enterprise switches and wireless controllers.

3H AGOIndustry Desk

U.S. military branches have disabled advertising trackers on government-issued phones and computers following reports that location data from these trackers was being used to target American forces in the Middle East.

4H AGOIndustry Desk

■ SUBSCRIBE TO THE DAILY BRIEF

ONE EMAIL, 5 STORIES, 06:00 UTC. UNSUBSCRIBE ANYTIME.