The question
Reasonable question — most "critical vulnerability" headlines are about servers or enterprise software most small businesses don't run. This one's different because of what it targets.
What we told them
The flaw sits in V8, the engine that runs JavaScript inside Chrome — it's Chrome's sixth zero-day of the year. A crafted webpage was enough to get code running on the visitor's machine, no download or install required. Google shipped a fix within days, and CISA added it to its Known Exploited Vulnerabilities list with a federal patch deadline, which tells you this wasn't theoretical — it was already being used.
Here's the part that actually matters for a small business: Chrome auto-updates by default. If nobody's disabled that setting and nobody's leaving the browser open for weeks without restarting it, most machines already have the fix. The real risk isn't the vulnerability — it's the handful of machines in every office where updates got turned off, or where Chrome hasn't been fully closed and reopened in a month.
- Check chrome://settings/help on a few machines. It shows the current version and whether it's up to date — thirty seconds per machine, worth doing after any "emergency patch" headline.
- A fully-updated Chrome doesn't help if it's never restarted. The update downloads in the background but doesn't apply until the browser relaunches. "I have 40 tabs open" is how a patched version keeps running vulnerable code for weeks.
- This is the sixth one this year — browser zero-days aren't rare anymore. The fix isn't a one-time check, it's making sure auto-update stays on and browsers get restarted regularly, permanently.
Browser zero-days move fast because browsers are the one piece of software every employee has open all day. Auto-update is your actual defense — the only job is making sure it's on, and that Chrome actually gets restarted often enough to use it.