Google has rushed out a Chrome update to fix a security flaw that attackers are already using in real-world attacks.
- What it is: A flaw in the V8 engine that powers Chrome, tracked as CVE-2026-85046, lets a malicious web page trick the browser into running attacker-controlled code inside its sandbox.
- Who is affected: Anyone running Chrome on Windows, Mac or Linux who has not yet picked up the latest update. This is the sixth actively exploited Chrome flaw fixed this year.
- What the risk is: Simply visiting a compromised or malicious page could be enough to trigger the exploit, though an attacker would typically need a second flaw to break out of the browser sandbox entirely.
- What action is needed: Update Chrome to version 152.0.7977.82 or later. Most systems pick this up automatically, but a manual check via Settings > About Chrome, followed by a restart, guarantees it is applied.
We recommend checking your Chrome version today rather than waiting for it to update on its own restart cycle. Source: The Hacker News.