Google has issued an emergency update for Chrome after it emerged that attackers are already exploiting a flaw in the browser. The problem sits in V8, the component that runs JavaScript on web pages, which means a prepared website can execute code inside the browser. For your organisation this is not an abstract risk: for most employees, the browser is where the working day actually happens.
What is going on
The vulnerability is tracked as CVE-2026-85046 and Google rates it as serious. What stands out is not the flaw itself but the timing: it was being abused before most systems had received the fix. Chrome version 152.0.7977.82 and later is safe. Because Microsoft Edge runs on the same engine, the warning applies there as well; that update followed later. Further background is available in the report on Security.NL.
Why a browser flaw weighs more heavily than it seems
Almost everything that keeps your organisation running is open in the browser: the mail environment, the accounting package, the CRM, the HR system. Anyone able to run code in that browser is uncomfortably close to the sessions your staff are logged into. No server breach is required, and no password needs to be stolen.
A browser flaw is also hard to isolate. You can take a vulnerable server offline, but you cannot ask your people to stay off the internet for a day. The only real measure is making sure the update is genuinely active on every workstation.
And that is where the misunderstanding sits
Chrome downloads updates automatically, so many business owners assume the matter is settled. That is only half true. The update is applied only after the browser has been fully closed and opened again. On machines where the laptop lid simply shuts each evening and the tabs stay put, a critical update can sit unused for days.
Three concrete steps for the coming working day:
- Ask your team to close the browser completely once and reopen it. Under Help and About Google Chrome you can see immediately which version is running.
- Do not forget the edge cases: point-of-sale systems, reception PCs, machines on the shop floor and laptops belonging to staff who have just returned from leave.
- Check that Edge and other Chromium-based browsers in your environment get the same attention.
From one-off updates to policy
Updating a browser once is manageable. The issue is that warnings like this now arrive weekly, and it is not work you want on your plate. What helps is visibility: knowing which devices exist, which versions they run and which ones are falling behind. That is exactly what we set up for clients through central patch management on workstations, including the software that is often overlooked, such as browsers, PDF readers and archive tools. Alerts like this one are then handled without anyone at your end having to chase them.
Would you like to know how many of your workstations are currently behind, and what it takes to keep that under control for good? Feel free to book a conversation with one of our engineers and we will look at your situation together.
Read also
When your IT supplier is breached instead of you
Ready to run worry-free?
Book a no-obligation introduction. We map your IT and security and show where the difference lies.
Book a call →
