Filed under: Cybersecurity — Patching — August 2026
What happened
Google shipped a Chrome update fixing 15 security bugs, including two rated critical (CVE-2026-76034, CVE-2026-76036). Both let a malicious or booby-trapped webpage run code outside the browser’s normal safety sandbox, meaning a bad site could reach beyond the browser and onto the computer itself. There’s no evidence yet that either is being used in real attacks, but critical browser bugs like these tend to get weaponized fast once details are public.
Why it matters to your business
Every employee’s browser is open all day, every day, and it’s the single most common way malware and scams reach a work PC. Microsoft Edge runs on the same underlying engine as Chrome, so it needs this same fix. One employee clicking the wrong link or landing on a compromised ad could be enough to hand an attacker a foothold on your network.
What to do this week
Chrome and Edge update themselves automatically, but don’t assume — check. In Chrome, go to chrome://settings/help and confirm you’re on version 150.0.7871.181 or later. In Edge, go to edge://settings/help and install any pending update. Either way, fully close and reopen the browser (not just the window) — updates don’t take effect until it restarts. If you manage several PCs, ask your IT provider to confirm the update pushed to every machine, not just your own.
The bigger picture
Browsers are the software your team uses the most and the software attackers target the most — this kind of critical patch comes around every few weeks, not just a few times a year. Staying current is the single cheapest thing a small business can do to close off this attack path. — Update Chrome now: Two critical vulnerabilities fixed (Malwarebytes)
Not sure your team’s browsers are actually up to date across the board? Book a free consult — https://micro1tech.com/contact/