Google Chrome Zero-Day Flaw Exploited in the Wild
V8 engine vulnerability and 12 total security updates address actively exploited bugs

Key Takeaways
- Google Chrome has been updated to address a zero-day flaw in the V8 engine that is actively being exploited in the wild.
- The update patches 12 total vulnerabilities, including the actively exploited zero-day and 11 other security issues.
- Successful exploitation could allow arbitrary code execution or denial of service.
- Users should update Chrome immediately to the latest available version.
- Detailed CVE identifiers and full exploit mechanics are pending complete disclosure.
Quick answers
- What happened?
- Google has released an emergency update for the Chrome browser patching a total of 12 vulnerabilities, including one actively exploited zero-day flaw in the V8 JavaScript engine. The update addresses a high-severity bug currently being used in targeted attacks, alongside 11 other security issues.
- Which products are affected?
- Google Chrome
- What should defenders do?
- Update Google Chrome to the latest version immediately. Enable automatic updates to ensure future security patches are applied promptly. Monitor official Google security bulletins for CVE details and further information on the exploited flaw.
Google has released an emergency security update for the Chrome browser addressing a total of 12 vulnerabilities. Among these, one flaw in the V8 JavaScript engine is reported to be actively exploited in the wild. The company has not disclosed detailed exploit mechanics, but successful exploitation could allow an attacker to execute arbitrary code or cause a denial of service on affected systems. The update also patches 11 additional vulnerabilities of varying severity. Users are strongly advised to update Chrome to the latest version to protect against the actively exploited bug and the other patched security issues. The update rollout is underway across all supported platforms.
Security Details
The actively exploited flaw resides in the V8 JavaScript engine of Google Chrome. Details regarding the specific CVE number and exact exploit methodology have not been fully disclosed in the initial report. The vulnerability is classified as high severity due to active in-the-wild exploitation. The patch also addresses 11 additional vulnerabilities in the Chrome browser.
Affected products
Google Chrome
Mitigation
Update Google Chrome to the latest version immediately. Enable automatic updates to ensure future security patches are applied promptly. Monitor official Google security bulletins for CVE details and further information on the exploited flaw.
Sources
BleepingComputer
Google warns of new Chrome zero-day flaw exploited in attacks
Sep 4, 2026 · 11:48
Original link
Related Security News

Star Blizzard Campaign Targets 100+ Organizations with Fake Event Invitations
Microsoft reports that the Russian state-sponsored threat actor Star Blizzard has been conducting a sustained campaign since January 2026, using fake event invitations to trick targets into installing a backdoor on Windows computers. The operation has affected more than 100 organizations, primarily in the U.S. and U.K., with victims tied to Ukraine. At least one infection has been confirmed, though the full extent of breaches and data exfiltration remains unverified.



