Google patches seventh actively exploited Chrome zero-day of 2026
Tuesday security update addresses 230 vulnerabilities; CISA adds zero-day to known exploited catalog

Key Takeaways
- Google patched 230 vulnerabilities in Chrome on Tuesday, including a seventh actively exploited zero-day in 2026.
- CISA has added the zero-day to its Known Exploited Vulnerabilities catalog with a mandatory patch deadline for federal agencies.
- Users should update Chrome to the latest version to protect against potential remote code execution or privilege escalation.
- The frequency of zero-day exploits in Chrome this year indicates a sustained high-threat environment for browser users.
Quick answers
- What happened?
- Google has released security updates for Chrome addressing a zero-day vulnerability actively exploited in the wild. This marks the seventh Chrome zero-day exploited in 2026. The update also patches 230 total vulnerabilities. CISA has added the vulnerability to its Known Exploited Vulnerabilities catalog, mandating federal agencies to patch by a deadline.
- Which products are affected?
- Chrome
- What should defenders do?
- Update Chrome to the latest version immediately. Enable automatic updates. Federal agencies must patch by the CISA deadline of September 23, 2026.
Google released security updates for Chrome on Tuesday, September 9, 2026, patching 230 vulnerabilities including an actively exploited zero-day bug. This is the seventh Chrome zero-day exploited in the wild so far this year. The company did not assign a CVE number in the initial report. The vulnerability is being actively exploited in the wild, though specific attack details were not disclosed. CISA has added the vulnerability to its Known Exploited Vulnerabilities (KEV) catalog, requiring federal civilian executive branch agencies to patch by September 23, 2026. Chrome users are strongly advised to update to the latest version immediately to mitigate the risk of remote code execution or privilege escalation.
Security Details
The patch addresses an actively exploited zero-day vulnerability in Chrome. This is the seventh such vulnerability exploited in the wild in 2026. CISA has added the vulnerability to its Known Exploited Vulnerabilities catalog. Successful exploitation could lead to remote code execution or privilege escalation.
Affected products
Chrome
Mitigation
Update Chrome to the latest version immediately. Enable automatic updates. Federal agencies must patch by the CISA deadline of September 23, 2026.
Sources
BleepingComputer
Google warns of new Chrome zero-day bug exploited in attacks
Sep 9, 2026 · 06:25
Original link
Related Security News
CISA Adds Two Citrix NetScaler Vulnerabilities to Known Exploited Catalog
The Cybersecurity and Infrastructure Security Agency (CISA) has added two new vulnerabilities to its Known Exploited Vulnerabilities (KEV) Catalog based on evidence of active exploitation. CVE-2026-88771 involves improper input validation and CVE-2026-88772 involves improper restriction of operations within the bounds of a memory buffer, both affecting Citrix NetScaler products. The additions trigger remediation requirements under Binding Operational Directive 26-04 for Federal Civilian Executive Branch agencies.




