Google has shipped an emergency security update for Chrome after discovering a zero-day vulnerability that attackers were already exploiting — the seventh such actively exploited flaw the company has patched in the browser so far in 2026. Zero-day vulnerabilities are security flaws that are discovered and exploited before a vendor has had the chance to release a fix, making them especially dangerous.
Google has historically kept technical details of these vulnerabilities under wraps until a majority of users have updated, in order to limit the window during which other attackers could reverse-engineer the flaw from the patch itself. Users are advised to make sure their browser is set to update automatically, or to manually trigger an update and restart the browser to apply the fix.
The steady drumbeat of Chrome zero-days this year underscores how browsers remain one of the most attractive targets for both cybercriminals and state-linked hacking groups, given how much sensitive activity — banking, email, corporate logins — now happens through a web browser rather than dedicated apps. Security researchers note that browser vulnerabilities are particularly valuable to attackers because a single flaw can potentially be used against billions of installations across every major operating system.
As always, security experts recommend keeping browsers and operating systems updated promptly, since the gap between a patch’s release and its widespread adoption is often when opportunistic attacks spike.