Tech Translated

IT Security & Technology Blog

Practical IT insights for Australian businesses. Our team covers cybersecurity advisories, compliance updates, and plain-English explainers on the technology your business relies on, published regularly as the landscape shifts.

Close-up of a person using a laptop — endpoint security and EDR for Sydney businesses

Chrome Zero-Day Under Active Attack — Update and Relaunch Today

Google has rushed out an emergency Chrome fix for a flaw attackers are already using in the wild. If your team runs Chrome or Edge — and almost every Australian business does — this one is worth doing before you close the laptop tonight.

On 4 September Google patched CVE-2026-85046, a high-severity “type confusion” bug in V8, the engine Chrome uses to run web code. The flaw lets an attacker run code on your machine just by getting you to open a booby-trapped web page — no click, no download needed. Google has confirmed a working exploit is already circulating, and the US cyber agency CISA has ordered federal agencies to patch by 18 September. Fixed builds are 152.0.7977.82 and later.

Actively exploited. A single malicious ad or phishing link is enough to trigger it, so treat this as a same-day job, not a next-sprint one.

Why this one matters for your business

This isn’t a niche server bug. Chrome is the browser most Australian offices sit in all day, and the same V8 engine ships inside Edge, Brave, Opera and Vivaldi. So if your staff standardise on Edge for Microsoft 365, you’re exposed too. The attack needs nothing more than someone visiting the wrong page.

What to do about it

Here’s the catch we see constantly across client environments: Chrome downloads the fix quietly, then does nothing until the browser is fully relaunched. Plenty of business laptops run for weeks without a proper restart — tabs left open, lid just closed at night — so the patch sits there, downloaded but not actually installed. A green “update” icon is not the same as a protected machine.

  • Force the relaunch. In Chrome go to More > Help > About Google Chrome, let it finish, then click Relaunch. Confirm the version reads 152.0.7977.82 or higher.
  • Don’t forget Edge. Update and restart every Chromium-based browser your team uses, not just Chrome.
  • Verify, don’t assume. If you run managed patching, push the update and check the relaunch actually happened on each device.
Managed patching and endpoint updates: we roll browser and system updates across your whole fleet and confirm they’ve landed — not just downloaded.

Written by Michael Sacco, All IT Services — a Sydney-based managed IT and cyber security provider supporting businesses across the Northern Beaches, wider Sydney, Central West NSW, Brisbane and Melbourne.

Not sure your team is actually patched?

We keep browsers and endpoints current across every device, and prove it — so a zero-day like this is closed within hours, not left to chance.

Related Guide

Cybersecurity for Sydney SMBs

Explore our complete guide to protecting your business from cyber threats.

Read the Full Guide →