Cybersecurity · September 2026
Your browser only patches when it restarts
"Probably most of them" is not an answer to the question of how many machines are patched.
On September 3, 2026, Google shipped a Chrome update fixing twelve security issues, including CVE-2026-85046, a type confusion flaw in the V8 JavaScript engine rated CVSS 8.8 and already being exploited in the wild. It was the sixth Chrome zero-day of the year. CISA added it to the Known Exploited Vulnerabilities catalog on September 4 and gave federal agencies until September 18 to remediate. The fix landed in Chrome 152.0.7977.82 and .83.
It is the difference between patched and merely eligible to be patched.
Because the flaw sits in V8, which is the engine underneath Chromium, other Chromium-based browsers including Microsoft Edge and Opera are affected depending on which version they are built on.
The part that catches people out
Browsers update themselves, which is why most organizations have stopped thinking about them entirely. But the update only takes effect when the browser actually restarts. Chrome downloads the new version in the background and then waits, and it will keep waiting.
Think about how your team actually works. Somebody has forty tabs open, has not closed the window since the last time their laptop was rebooted, and that laptop gets a lid-close rather than a shutdown at the end of every day. That machine can sit with an available patch, unapplied, for weeks. The little update icon is there. Nobody looks at it.
Why this matters more than it used to
The browser is where the work is now. Microsoft 365, your accounting platform, your CRM, your bank, your practice management system. The browser holds the sessions, the saved credentials, and the tokens for nearly everything your business runs on. A flaw that lets an attacker execute code by getting someone to load a web page is a flaw that sits directly in front of all of it.
The question to ask today
What percentage of your machines are on Chrome 152.0.7977.82 or later right now?
If the answer is "probably most of them," that is not an answer, that is a gap. It means nobody can see browser versions across your estate, which means nobody can see whether any patch has landed, this one or the next one.
What good looks like
- Browser versions are visible centrally, alongside operating system patch status
- Machines are restarted on a known cadence rather than accumulating months of uptime
- Staff know that "restart to update" is not a suggestion they can defer indefinitely
- Somebody is notified when a machine falls behind, without having to go looking
None of this is exotic. It is ordinary endpoint visibility, and it is the difference between patched and merely eligible to be patched. It is also the kind of thing that is invisible when it is working, which is exactly why it tends to get skipped. We cover browser and endpoint patch status as part of ongoing managed IT, because auto-update on its own has never been the whole answer.
Get started
Questions about your own setup?
A free assessment turns general guidance into specific next steps for your organization. No pressure, no obligation.