A fixed browser flaw is being exploited
Google released a desktop Chrome stable-channel update on 3 September which includes a fix for CVE-2026-85046, a high-severity type-confusion vulnerability in the V8 JavaScript engine. The company says it is aware that an exploit for this vulnerability exists in the wild. The update also addresses other security defects, but Google makes the in-the-wild statement specifically about CVE-2026-85046.
On 4 September, the US Cybersecurity and Infrastructure Security Agency added the same vulnerability to its Known Exploited Vulnerabilities catalogue, saying the addition was based on evidence of active exploitation. CISA encourages organisations to prioritise remediation of catalogue vulnerabilities. Its operational directive is written for US federal agencies, so its deadlines do not bind UK businesses, but the exploitation finding is a useful reason to move this browser update ahead of routine maintenance.
[1][2]The version on the endpoint is what matters
Google identifies the fixed desktop builds as 152.0.7977.82 or .83 for Windows and macOS, and 152.0.7977.82 for Linux. The company says the release will roll out over the coming days and weeks. That staged rollout means an available update is not the same as a completed update across the estate.
Chrome can download an update while continuing to run the older browser process until it is restarted. Long-lived sessions, rarely rebooted shared machines and devices outside central management can therefore remain on an earlier build. A policy that permits automatic updates is useful, but evidence from the running version is stronger than evidence from the policy alone.
The primary sources establish exploitation in the wild, not that every vulnerable browser has been targeted or compromised. Google has restricted some bug detail while users update. Keep the response proportionate: verify versions and investigate suspicious activity where local evidence warrants it, without inventing a campaign, target set or delivery method that the advisories do not describe.
[1][2]Update, restart and measure coverage
Ask users and support teams to allow Chrome to update and then restart the browser. On managed devices, use browser or endpoint-management reporting to confirm the running version after restart. Record machines that are offline, unmanaged or unable to take the current stable release, assign each an owner, and follow them through rather than treating the first deployment command as completion.
Check specialist and shared systems as well as ordinary laptops: reception kiosks, meeting-room devices, test machines, virtual desktops and supplier-managed endpoints can all run browsers while sitting outside the most visible update dashboard. Where a legacy application prevents a supported browser update, isolate that dependency and reduce exposure while a replacement plan is agreed; leaving the general-purpose browser old is not a durable compatibility strategy.
Organisations using other Chromium-based browsers should consult that browser vendor's own release information and management data rather than assuming a Chrome build number applies. The immediate facts verified here concern desktop Google Chrome.
- Update desktop Chrome to the fixed stable build or later.
- Restart the browser so the updated process is running.
- Verify deployed versions through management reporting, not policy alone.
- Find offline, unmanaged and exception devices and give each an owner.
- Use the relevant vendor guidance for other Chromium-based browsers.
The Beekeeper view
Browser patching is an exposure-management task, not merely a software-distribution task. The browser routinely processes untrusted internet content, so a known exploited flaw deserves a short path from vendor release to a verified running build.
The useful completion measure is coverage: how many active endpoints are on the fixed version, how many are still exposed, and who owns every exception. Automatic updating does much of the work. The restart and the evidence close the gap.
[1][2]Primary sources
- Stable Channel Update for Desktop — Google Chrome, 3 September 2026
- CISA Adds One Known Exploited Vulnerability to Catalog — Cybersecurity and Infrastructure Security Agency, 4 September 2026
Beekeeper field notes summarise primary advisories for a UK business audience. Always follow the affected vendor’s current instructions for your exact product and version.