Google issues emergency update for Chrome after unknown bug detected
Please refresh the page or navigate to another page on the site to be automatically logged in Please refresh your browser to be logged in
Swipe for article
The Independent Security channel is brought to you by Bitdefender
Google has been forced to issue an emergency update for its Chrome browser after uncovering the most serious type of cyber security flaw.
Researcher Salvatore Gulizia discovered the bug within the hugely popular web browser, which has approximately 3.6 billion users worldwide, and reported it to Google .
The US tech giant noted that it is something known as a zero-day vulnerability , which has already been exploited by hackers.
This type of vulnerability is particularly concerning as it is previously unknown to software developers, meaning there have been zero days to protect against it.
The update for Windows, macOS and Linux includes 12 security fixes for the flaw, identified as CVE-2026-85046.
Google did not provide specific details the security vulnerability in order to give users time to update their browser.
“Google is aware that an exploit for CVE-2026-85046 exists in the wild,” Google said in an advisory the issue.
“Access to bug details and links may be kept restricted until a majority of users are updated with a fix.”
The ideal summer spot? Away from scams.
Get All-in-One Protection for Your Digital Life
The ideal summer spot? Away from scams.
Get All-in-One Protection for Your Digital Life
It is understood that the security issue could be exploited by tricking someone into visiting an HTML page containing malicious code, which would potentially give attackers control of the affected browser tab.
This could allow them to crash the system, execute malicious code, or steal sensitive data.
No details were provided who is exploiting the security flaw, how many people have fallen victim to it, or who is being targeted.
The Independent has reached out to Google for .
Earlier this year, researchers at Google Threat Intelligence Group (GTIG) discovered the first evidence of hackers using artificial intelligence to create a zero-day vulnerability.
“For the first time, GTIG has identified a threat actor using a zero-day exploit that we believe was developed with AI,” the researchers wrote in a report in May.
“The criminal threat actor planned to use it in a mass exploitation event but our proactive counter discovery may have prevented its use.”
Google has advised Chrome users to protect themselves against the latest zero-day exploit by updating their web browser through Settings > Chrome and installing any updates available.
Join our commenting forum
Join thought-provoking conversations, follow other Independent readers and see their replies
Thank you for registering
Please refresh the page or navigate to another page on the site to be automatically logged in Please refresh your browser to be logged in
The full story
This article is one source in a clustered incident — the cluster page carries the summary, timeline and every other outlet covering it.
