Google has released an emergency security update for its Chrome browser to address a critical zero-day vulnerability that was already being exploited in the wild. The flaw, identified as CVE-2026- , resides in Chrome's sandboxed renderer process and could allow attackers to execute arbitrary code remotely. The patch was issued on September 4, 2026, following reports of active attacks targeting the vulnerability. Google confirmed the fix in Chrome version 115.0.5790.170 for desktop platforms.
The vulnerability stems from a use-after-free error in the browser's rendering engine, which could be triggered by malicious web content. When exploited, it could allow an attacker to bypass Chrome's sandbox protections and gain elevated privileges on the affected system. Security researchers noted that the exploit chain likely required user interaction, such as visiting a compromised website, but once triggered, it could lead to full system compromise. Google did not disclose technical details publicly to prevent further abuse while users updated their browsers.
Users are strongly advised to update Chrome immediately to the latest version through the browser's built-in update mechanism or by downloading it directly from Google's official site. Enterprise administrators should prioritize deployment via centralized management tools. Google emphasized that keeping software up to date remains the most effective defense against such threats. The company also encouraged users to enable enhanced safe browsing features for additional protection against phishing and malware.
How serious is this Chrome zero-day? This vulnerability was rated critical due to its potential for remote code execution and active exploitation in the wild, though successful attacks likely required user interaction with malicious content.
Can the exploit work without user interaction? Based on available information, the exploit chain appears to have required some form of user interaction, such as clicking a link or visiting a compromised site, rather than being fully automatic.
Is my data at risk if I haven't updated yet? If you visited a malicious site while running an unpatched version, there is a risk of compromise; updating now prevents future exposure but does not remediate past incidents.