Google Patches Chrome's 7th Exploited Zero-Day of 2026
Google patched the seventh actively exploited Chrome zero-day of 2026 on September 9, in a 230-vulnerability update. CVE designation pending.

Confirmed. Google released a Chrome security update on September 9 patching another actively exploited zero-day: the seventh Chrome zero-day fixed under active exploitation since January, per BleepingComputer. The update covers 230 vulnerabilities total.
CVE designation: not confirmed in available source summaries at time of publication.
Pattern: seven zero-days in nine months
The count holds context. Seven exploited Chrome zero-days in a calendar year is in range with prior years’ browser targeting volume. The previous Chrome zero-day, CVE-2026-85046 (V8 type confusion), was patched five days ago on September 4. Back-to-back patches within the same update cycle happen when researchers report bugs in clusters, or when an active exploitation event triggers emergency disclosure alongside an already-scheduled update.
Chrome’s patch cycle compresses the exploitation window for end users who have automatic updates running. The risk concentrates at the managed-fleet end, where update rollouts are delayed or gated by change-control processes.
September 9 patch load
This zero-day lands on the same day as the Microsoft September Patch Tuesday record (974 CVEs, two actively exploited Windows zero-days) and the CISA KEV addition for N-able N-central. All three involve confirmed active exploitation. Patch cycle volumes are high this week.
Related: Chrome Patches Exploited V8 Zero-Day: Update Now | N-able N-central Auth Bypass Added to CISA KEV | Microsoft Patches Record 974 Vulns, 2 Zero-Days
Found this useful? Share it.


