Google security advisory (AV26-844)
Canada's Cyber Centre relays a Google advisory urging updates for Chrome versions prior to 151.0.7922.173 to address vulnerabilities.
The Canadian Centre for Cyber Security issued advisory AV26-844, noting that as of August 20, 2026, Google Chrome prior to version 151.0.7922.173 is affected by vulnerabilities. The Cyber Centre encourages users and administrators to review Google's advisory and apply the necessary updates. No exploitation details or CVE identifiers are provided in the bulletin text.
Google security advisory (AV26-904)
Google patches Chrome CVE-2026-87491, exploited in the wild and added to CISA's KEV; users should update to 153.0.8010.37.
Google released a stable channel desktop update fixing vulnerabilities in Chrome prior to 153.0.8010.37. Google confirmed that an exploit for CVE-2026-87491 exists in the wild, and CISA added the flaw to its Known Exploited Vulnerabilities catalog on September 9, 2026. The Canadian Centre for Cyber Security issued advisory AV26-904 urging users and administrators to apply the update.
Google security advisory (AV26-926)
Canadian Cyber Centre relays Google's Chrome 153.0.8010.48 stable channel update fixing unspecified desktop vulnerabilities.
The Canadian Centre for Cyber Security issued advisory AV26-926 noting that Google Chrome versions prior to 153.0.8010.48 are affected by vulnerabilities. The advisory provides no CVE details or exploitation information and encourages users and administrators to apply the stable channel desktop update for September 15, 2026.
Android 17 Adds OS-Wide ECH to Hide Website Visits From Network Providers
Google announced Android 17 will enforce OS-wide Encrypted Client Hello with ECH GREASE, plus Certificate Transparency by default and carrier 2G disablement.
Google announced Android 17 network security protections headlined by OS-wide support for Encrypted Client Hello (ECH), with ECH GREASE enabled by default so connections to non-ECH servers look identical. Google's Jigsaw noted OkHttp has integrated ECH, letting third-party Android apps adopt the standard. The release also enforces Local Network Protection permission prompts, enables Certificate Transparency by default, and lets carriers turn off 2G by default to prevent downgrade attacks, rogue base stations, and SMS blasters. ECH was previously added to Chrome 117 and Firefox 118 at the browser level only.
Google security advisory (AV26-874)
Canada's Cyber Centre relayed a Google advisory urging users to update Chrome to 152.0.7977.75 or later to fix unspecified vulnerabilities.
The Canadian Centre for Cyber Security issued advisory AV26-874 on September 2, 2026, noting vulnerabilities affecting Google Chrome prior to version 152.0.7977.75. The advisory points to Google's Stable Channel Update for Desktop and encourages users and administrators to review the vendor link and apply updates as they become available.
September 2026 Patch Tuesday forecast: All we need is more time
September 2026 Patch Tuesday forecast expects record CVE volume after August's 398 fixes, with SharePoint flaws CVE-2026-55040 and CVE-2026-63520 actively exploited.
This Patch Tuesday forecast column notes August 2026 Patch Tuesday was the second largest ever with 398 resolved CVEs, yet only one was confirmed actively exploited. SharePoint flaws CVE-2026-55040 and CVE-2026-63520 are being chained for authentication bypass and remote code execution in active attacks against unpatched servers. Microsoft Defender's ShieldBreak elevation of privilege flaw (CVE-2026-69414) is publicly disclosed with PoC code and a fix is expected, while Chrome CVE-2026-85046 was reported exploited in the wild. Several products, including Windows 11 24H2 Home/Pro and Exchange Server 2016/2019 ESU, reach end of support in October 2026.