01303 883111 info@meridian-micro.com Support Login
meridianmicro
Get in Touch
01303 883111 info@meridian-micro.com
Security

Google Chrome CVE-2026-85046 Zero-Day Under Active Exploit September 2026: What UK SMEs Must Patch Immediately

September 7, 2026 Meridian Micro

Google released an emergency security update for Chrome this week to patch CVE-2026-85046, a critical zero-day vulnerability in the V8 JavaScript engine that is being actively exploited in the wild.
The US Cybersecurity and Infrastructure Security Agency (CISA) added CVE-2026-85046 to its Known Exploited Vulnerabilities (KEV) catalog on 4 September 2026, requiring Federal Civilian Executive Branch agencies to apply patches by 18 September 2026
. For UK SMEs relying on Chrome as their primary business browser, immediate patching is not optional—it’s a critical security requirement that must be completed this week.

This marks the latest in a concerning pattern of browser-based attacks targeting businesses in 2026.
Google reported that this week’s Chrome update—version 152.0.7977.82/.83—addressed 12 CVEs, with CVE-2026-85046 confirmed as exploited in the wild
. The vulnerability affects the V8 JavaScript engine, which processes web content in every Chrome tab, making exploitation possible simply by visiting a compromised or malicious website.

What Is CVE-2026-85046 and Why Does It Matter to Kent SMEs?

The actively exploited Chrome V8 flaw enables arbitrary code execution inside the sandbox through a crafted HTML page
. In practical terms, this means that an attacker can execute malicious code on a user’s computer simply by convincing them to visit a specially crafted website—no additional user interaction required beyond loading the page.

For UK SMEs, the risk is substantial for several reasons:

This vulnerability arrives during an already challenging month for UK SMEs. As we covered in our Microsoft September 2026 Patch Tuesday preparation guide, organisations face mounting pressure to deploy security updates within increasingly compressed timeframes.

How to Check Your Chrome Version and Update Immediately

Every UK SME must verify that all Chrome installations across their organisation have been updated to version 152.0.7977.82 (Windows and macOS) or 152.0.7977.83 (Linux) or later. Here’s how to check and update:

For Individual Users

  1. Open Google Chrome
  2. Click the three-dot menu (top-right corner)
  3. Navigate to Help → About Google Chrome
  4. Chrome will automatically check for updates and install them
  5. Click Relaunch to complete the update

For IT Administrators Managing Fleet Deployments

If your organisation uses Google Chrome Enterprise with centralised management:

For organisations using Microsoft Edge (which shares Chromium codebase with Chrome), verify that you’re running the latest version as Microsoft typically incorporates Google’s security fixes into Edge updates, though on a slightly delayed schedule.

Why CISA’s 18 September Deadline Matters for UK Organisations

Whilst CISA’s Known Exploited Vulnerabilities catalog technically applies only to US federal agencies, security-conscious UK SMEs should treat CISA KEV additions as mandatory patching triggers for their own organisations. The 18 September 2026 deadline represents the absolute maximum window that even government agencies—with their extensive security resources—consider acceptable for a known-exploited vulnerability.

For UK SMEs with more limited security teams and no dedicated security operations centre, the practical deadline should be much shorter—ideally within 24-48 hours of patch availability. This aligns with Microsoft’s current recommendation to deploy Windows updates within 3 days, reflecting the accelerated threat landscape facing businesses in 2026.

Cyber Insurance Implications

For UK SMEs with cyber insurance policies, failure to patch known-exploited vulnerabilities within reasonable timeframes can void coverage. As we detailed in our analysis of technical controls UK insurers now demand, patch management processes have become a standard requirement in 2026 policy renewals. An incident stemming from an unpatched, publicly known vulnerability—especially one on CISA’s KEV list—will likely be excluded from coverage.

Browser Security in the 2026 Threat Landscape

The Chrome zero-day comes amid a broader pattern of browser-based attacks intensifying throughout 2026. Web browsers have become the primary attack surface for UK SMEs because they:

Recent research found that 42% of UK SME owners and managers cite cybersecurity as the main obstacle to further digitalisation in 2026
, yet many organisations still lack systematic processes for managing browser security updates across their workforce.

What Kent SMEs Must Do This Week

Meridian Micro Limited recommends that all Kent and South East businesses complete the following actions before the weekend:

  1. Audit all Chrome installations: Use your endpoint management tools or manual checks to verify Chrome versions across every device in your organisation, including remote workers.
  2. Deploy updates immediately: Update all Chrome browsers to version 152.0.7977.82/.83 or later. Do not wait for your normal patch cycle.
  3. Restart browsers: Chrome updates require a browser restart to take effect. Ensure all users have relaunched Chrome after the update installs.
  4. Review Microsoft Edge versions: If your organisation uses Edge, verify you’re running the latest version and have automatic updates enabled.
  5. Document the update: Record completion of this emergency update in your IT change log—this documentation matters for compliance and insurance purposes.
  6. Prepare for Tuesday’s patches: With Microsoft Patch Tuesday releasing on 8 September, your team should already be preparing for the next wave of security updates.

Consider Managed Browser Updates

If your organisation struggles to keep pace with the accelerating volume of security updates in 2026, a managed IT support service can automate browser patching whilst maintaining control over deployment timing and testing. This is particularly important for businesses that have discovered—often too late—that individual employees have disabled automatic updates or are running outdated browser versions.

Ongoing Browser Security for UK SMEs

Beyond this immediate Chrome zero-day, UK SMEs should implement systematic browser security management:

The Chrome CVE-2026-85046 zero-day reinforces a critical lesson for UK SMEs: browser security is infrastructure security. In 2026, every employee’s browser is a potential entry point to your business systems, data, and customer information. Systematic, rapid patching of browser vulnerabilities must be a core component of your IT security posture.

If your Kent or South East business needs assistance with browser security, emergency patching, or systematic IT security management, Meridian Micro Limited provides expert IT support tailored to SME requirements. Contact our team on 01303 883111 to discuss how we can help protect your business from the accelerating threat landscape facing UK SMEs in 2026.