Web_Logo
Remote Support
Security Alert: Chrome Zero-Day Under Active Attack, Update Now
Home » Security Alerts  »  Security Alert: Chrome Zero-Day Under Active Attack, Update Now

Security Alert: Chrome Zero-Day Under Active Attack, Update Now

Google has released an emergency update for the Chrome browser to fix a security flaw, known as CVE-2026-11645, that criminals are already using in real attacks. Simply visiting a malicious web page can be enough to compromise the browser, so this one should not wait for your normal update cycle.

  • What it is: A flaw in the engine Chrome uses to run web page code. A crafted web page can use it to run attacker code inside the browser.
  • Who is affected: Any business using Google Chrome on Windows, Mac or Linux. Other browsers built on the same engine, such as Microsoft Edge, will receive their own updates shortly.
  • The risk: Google has confirmed the flaw is being exploited in the wild, and the US cyber security agency CISA has added it to its Known Exploited Vulnerabilities catalogue. This is the fifth Chrome zero-day fixed this year.
  • What to do: Update Chrome to version 149.0.7827.102 or later. Click the three dots menu, then Help, then About Google Chrome, and relaunch the browser once the update downloads. Staff should restart their browsers today.

We recommend businesses confirm all staff browsers have updated and relaunched, as Chrome only applies updates after a restart. More detail is available from Help Net Security and The Hacker News.