Google released an emergency security update for Chrome this week to patch CVE-2026-85046, a critical zero-day vulnerability in the V8 JavaScript engine that is being actively exploited in the wild.
The US Cybersecurity and Infrastructure Security Agency (CISA) added CVE-2026-85046 to its Known Exploited Vulnerabilities (KEV) catalog on 4 September 2026, requiring Federal Civilian Executive Branch agencies to apply patches by 18 September 2026
. For UK SMEs relying on Chrome as their primary business browser, immediate patching is not optional—it’s a critical security requirement that must be completed this week.
This marks the latest in a concerning pattern of browser-based attacks targeting businesses in 2026.
Google reported that this week’s Chrome update—version 152.0.7977.82/.83—addressed 12 CVEs, with CVE-2026-85046 confirmed as exploited in the wild
. The vulnerability affects the V8 JavaScript engine, which processes web content in every Chrome tab, making exploitation possible simply by visiting a compromised or malicious website.
What Is CVE-2026-85046 and Why Does It Matter to Kent SMEs?
The actively exploited Chrome V8 flaw enables arbitrary code execution inside the sandbox through a crafted HTML page
. In practical terms, this means that an attacker can execute malicious code on a user’s computer simply by convincing them to visit a specially crafted website—no additional user interaction required beyond loading the page.
For UK SMEs, the risk is substantial for several reasons:
- Chrome dominates business browsing: Most UK SMEs have standardised on Chrome or Chromium-based browsers (including Microsoft Edge) for their workforce, meaning a single vulnerability affects nearly every computer in the organisation.
- Active exploitation confirmed: Unlike theoretical vulnerabilities, this flaw is being used in real attacks right now. Threat actors are already weaponising CVE-2026-85046 against organisations.
- Minimal attack complexity: Exploitation requires only that an employee visit a malicious website, making phishing campaigns and compromised legitimate sites effective attack vectors.
- Sandbox escape potential: Whilst the initial exploit operates within Chrome’s sandbox, V8 vulnerabilities are frequently chained with additional exploits to achieve full system compromise.
This vulnerability arrives during an already challenging month for UK SMEs. As we covered in our Microsoft September 2026 Patch Tuesday preparation guide, organisations face mounting pressure to deploy security updates within increasingly compressed timeframes.
How to Check Your Chrome Version and Update Immediately
Every UK SME must verify that all Chrome installations across their organisation have been updated to version 152.0.7977.82 (Windows and macOS) or 152.0.7977.83 (Linux) or later. Here’s how to check and update:
For Individual Users
- Open Google Chrome
- Click the three-dot menu (top-right corner)
- Navigate to Help → About Google Chrome
- Chrome will automatically check for updates and install them
- Click Relaunch to complete the update
For IT Administrators Managing Fleet Deployments
If your organisation uses Google Chrome Enterprise with centralised management:
- Verify that automatic updates are enabled in your Google Admin Console or equivalent management platform
- Use your endpoint management solution to audit Chrome versions across all devices
- Prioritise devices used by staff with elevated privileges or access to sensitive data
- Force-close and relaunch Chrome remotely where necessary to complete updates
For organisations using Microsoft Edge (which shares Chromium codebase with Chrome), verify that you’re running the latest version as Microsoft typically incorporates Google’s security fixes into Edge updates, though on a slightly delayed schedule.
Why CISA’s 18 September Deadline Matters for UK Organisations
Whilst CISA’s Known Exploited Vulnerabilities catalog technically applies only to US federal agencies, security-conscious UK SMEs should treat CISA KEV additions as mandatory patching triggers for their own organisations. The 18 September 2026 deadline represents the absolute maximum window that even government agencies—with their extensive security resources—consider acceptable for a known-exploited vulnerability.
For UK SMEs with more limited security teams and no dedicated security operations centre, the practical deadline should be much shorter—ideally within 24-48 hours of patch availability. This aligns with Microsoft’s current recommendation to deploy Windows updates within 3 days, reflecting the accelerated threat landscape facing businesses in 2026.
Cyber Insurance Implications
For UK SMEs with cyber insurance policies, failure to patch known-exploited vulnerabilities within reasonable timeframes can void coverage. As we detailed in our analysis of technical controls UK insurers now demand, patch management processes have become a standard requirement in 2026 policy renewals. An incident stemming from an unpatched, publicly known vulnerability—especially one on CISA’s KEV list—will likely be excluded from coverage.
Browser Security in the 2026 Threat Landscape
The Chrome zero-day comes amid a broader pattern of browser-based attacks intensifying throughout 2026. Web browsers have become the primary attack surface for UK SMEs because they:
- Process untrusted content from the internet continuously throughout the business day
- Have extensive privileges to access local system resources, stored credentials, and corporate web applications
- Run JavaScript code from thousands of different sources, including advertising networks and third-party widgets on otherwise legitimate websites
- Store authentication tokens for cloud services, making them high-value targets for credential theft
Recent research found that 42% of UK SME owners and managers cite cybersecurity as the main obstacle to further digitalisation in 2026
, yet many organisations still lack systematic processes for managing browser security updates across their workforce.
What Kent SMEs Must Do This Week
Meridian Micro Limited recommends that all Kent and South East businesses complete the following actions before the weekend:
- Audit all Chrome installations: Use your endpoint management tools or manual checks to verify Chrome versions across every device in your organisation, including remote workers.
- Deploy updates immediately: Update all Chrome browsers to version 152.0.7977.82/.83 or later. Do not wait for your normal patch cycle.
- Restart browsers: Chrome updates require a browser restart to take effect. Ensure all users have relaunched Chrome after the update installs.
- Review Microsoft Edge versions: If your organisation uses Edge, verify you’re running the latest version and have automatic updates enabled.
- Document the update: Record completion of this emergency update in your IT change log—this documentation matters for compliance and insurance purposes.
- Prepare for Tuesday’s patches: With Microsoft Patch Tuesday releasing on 8 September, your team should already be preparing for the next wave of security updates.
Consider Managed Browser Updates
If your organisation struggles to keep pace with the accelerating volume of security updates in 2026, a managed IT support service can automate browser patching whilst maintaining control over deployment timing and testing. This is particularly important for businesses that have discovered—often too late—that individual employees have disabled automatic updates or are running outdated browser versions.
Ongoing Browser Security for UK SMEs
Beyond this immediate Chrome zero-day, UK SMEs should implement systematic browser security management:
- Enable automatic updates: Configure Chrome (and other browsers) to update automatically in the background, minimising the window of vulnerability.
- Enforce browser versions: Use Group Policy, Intune, or your endpoint management platform to enforce minimum browser versions and block outdated installations.
- Implement extension controls: Review and whitelist approved browser extensions; malicious or vulnerable extensions are an increasingly common attack vector.
- Deploy security headers: If you manage web applications, implement Content Security Policy and other headers to limit the damage from browser-based attacks.
- Monitor browser versions: Include browser version tracking in your regular IT asset audits to identify outdated installations before they become security incidents.
The Chrome CVE-2026-85046 zero-day reinforces a critical lesson for UK SMEs: browser security is infrastructure security. In 2026, every employee’s browser is a potential entry point to your business systems, data, and customer information. Systematic, rapid patching of browser vulnerabilities must be a core component of your IT security posture.
If your Kent or South East business needs assistance with browser security, emergency patching, or systematic IT security management, Meridian Micro Limited provides expert IT support tailored to SME requirements. Contact our team on 01303 883111 to discuss how we can help protect your business from the accelerating threat landscape facing UK SMEs in 2026.