Google has released an emergency Chrome update after discovering a previously unknown security flaw that hackers are already exploiting.
Google has issued an emergency update for its Chrome web browser after discovering a serious security vulnerability that is already being exploited by hackers.
The flaw, identified as CVE-2026-85046, is a so-called zero-day vulnerability.
These are particularly dangerous because they are unknown to software developers until they are discovered or exploited, leaving little or no time to develop protections.
Security researcher Salvatore Gulizia reported the vulnerability to Google, which has now released an update for Chrome on Windows, macOS and Linux containing 12 security fixes.
Google has not revealed detailed information about the flaw, allowing users time to install the update before more information becomes available.
The company said in a security advisory: “Google is aware that an exploit for CVE-2026-85046 exists in the wild.
“Access to bug details and links may be kept restricted until a majority of users are updated with a fix.”
The vulnerability is understood to potentially be triggered when someone visits an HTML page containing malicious code. Attackers could potentially gain control of the affected browser tab, allowing them to crash systems, execute malicious code or steal sensitive information.
Google has not said who is exploiting the vulnerability, how many people may have been affected or whether particular groups are being targeted.
Chrome is one of the world’s most widely used web browsers, with approximately 3.6 billion users worldwide, making security flaws in the software an attractive target for cyber criminals.
The latest discovery comes as researchers warn that artificial intelligence is also making it easier for hackers to identify and exploit previously unknown vulnerabilities.
Earlier this year, Google’s Threat Intelligence Group said it had found evidence of a threat actor using AI to develop a zero-day exploit.
Researchers said in a report published in May: “For the first time, GTIG has identified a threat actor using a zero-day exploit that we believe was developed with AI.”
They said the attacker had planned to use the exploit in a mass exploitation campaign, but Google’s discovery may have prevented it from being deployed.
Google is urging Chrome users to install the latest update as soon as possible.
Users can check whether an update is available by opening Chrome, selecting Settings, then About Chrome.
The browser should automatically check for updates and install any available security fixes.
Given that the latest vulnerability is already being exploited, users are advised not to delay the update.
Google issues emergency Chrome update as unknown bug is detected







