ITSECURITY.GURU WHAT HAPPENED · DOES IT AFFECT YOU · WHAT TO DO
BoardDaily Briefing › 8 Sept 2026
Daily Briefing

Tuesday, 8 September 2026

A Chrome flaw CISA lists as known-exploited tops six Google fixes; PEEP turns Chrome and Edge into backdoors

CISA lists CVE-2026-85046 in Chrome as known to be exploited, Google has shipped fixes for six Chrome flaws in total, and The Hacker News reports that researchers have disclosed a Chromium post-exploitation toolkit named PEEP.

CISA lists CVE-2026-85046, a Google Chrome vulnerability, as known to be exploited and has added it to its Known Exploited Vulnerabilities catalog. It carries CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H, a base score of 8.8. Google's advisory lists Chrome up to the fix in 152.0.7977.82 as affected. The vector requires user interaction and delivers high impact to confidentiality, integrity and availability. This is the item to move on first: it is the only one of the day's Chrome flaws that CISA records as known to be exploited.

Google's stable-channel updates cover five further Chrome flaws, none of which CISA currently lists as exploited. CVE-2026-84325 carries CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H, a base score of 9.8, and requires no user interaction. CVE-2026-84354 scores 9.6 (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H). CVE-2026-84324 scores 9.0 (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H). CVE-2026-84350 scores 8.8 (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H). CVE-2026-84351 scores 8.3 (CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:H). Google's advisory lists Chrome up to the fix in 152.0.7977.75 as affected for all five.

What to do: Google's advisory says to move to the fixed releases — 152.0.7977.82 for CVE-2026-85046 (https://chromereleases.googleblog.com/2026/09/stable-channel-update-for-desktop_01882797386.html), and 152.0.7977.75 for the other five (https://chromereleases.googleblog.com/2026/09/stable-channel-update-for-desktop.html). For the exploited flaw, CISA directs stakeholders to apply mitigations in accordance with vendor instructions and its BOD 26-04 guidance, or discontinue use of the product if mitigations are unavailable (https://www.cisa.gov/known-exploited-vulnerabilities-catalog).

Separately, The Hacker News reported that researchers have disclosed PEEP, a Chromium-based post-exploitation toolkit that masquerades as a bookmarks extension and whose installer injects the extension directly into Chrome and Edge profiles to run host commands. The Hacker News says PEEP requires prior administrative or code-execution access, so treat it as a persistence and command-execution mechanism to hunt for after a compromise, not an initial-access vector (https://thehackernews.com/2026/09/peep-turns-chrome-and-edge-into-post.html). Review browser profiles for unexpected injected extensions and monitor browser processes spawning host commands.

In other reporting, Help Net Security published a video with Intel 471's Dave Ross on how ransomware groups run negotiations, from researching a victim's revenue and insurance coverage to test decryption (https://www.helpnetsecurity.com/2026/09/08/ransomware-negotiation-tactics-video/) — useful background for incident-response planning.

Summarized from the linked reports and the advisory record by the desk. Verify against the original sources before citing.

All briefings →