September 2026 Priority Technology Brief
An actively exploited Chrome vulnerability, confirmed Windows 11 problems and an unusually busy week of Linux security updates lead the developments worth acting on now.
Update Chrome: Google confirms active exploitation
What changed: Google released two Chrome security updates in three days. The September 1 update fixed 26 vulnerabilities, including two rated critical. A second update on September 3 fixed 12 more vulnerabilities, and Google confirmed that an exploit for CVE-2026-85046, a high-severity V8 type-confusion flaw, exists in the wild.
Who is affected: Chrome users on Windows, macOS, Linux and Android. The corrected desktop Stable build is 152.0.7977.82/.83 for Windows and Mac and 152.0.7977.82 for Linux. Some users may already receive a newer Chrome 153 build, which is also acceptable. Android Chrome 152.0.7977.82 includes the corresponding desktop security fixes unless Google notes otherwise.
Why it matters: “In the wild” means exploitation is no longer theoretical. Browsers process untrusted web content all day, so delaying a browser update leaves an avoidable opening even when antivirus software is installed.
Security leads; Workspace personalization expands
Chrome is the urgent Google action. Workspace also gained a useful productivity capability, but it should be adopted with sensible information-handling rules.
Chrome received 38 security fixes across two releases
The September 1 Chrome release addressed 26 security issues, including critical use-after-free flaws in Shared Tab Groups and WebGL. The superseding September 3 release added 12 more fixes and addressed the vulnerability Google says is being exploited.
Recommended decision: Treat browser patching as the week’s first technology task. The current September 3 build or any later Stable release is the target.
Gemini custom instructions expand across Workspace
Beginning September 2, Google started rolling out persistent Gemini instructions to Ask Gemini in Drive and Chat and to the Gemini side panels in Gmail, Sheets and Slides. Instructions created in one supported Workspace surface can guide responses across the others.
Why it matters: Individuals and teams can stop repeating preferences such as tone, response length and formatting. Google says there is no administrator control for this feature, so organizations should provide users with clear internal guidance.
Recommended decision: Use the feature for non-sensitive working preferences and approved brand-writing guidance. Do not place passwords, confidential client information or other secrets in persistent instructions.
Windows 11 problems are confirmed; a security change is coming
There was no September Patch Tuesday release within this briefing period. Microsoft did, however, confirm problems caused or exposed by recent Windows updates and announced an October security rollout.
Some Windows 11 backgrounds turn solid black
Microsoft says updates released August 27 and later can prevent desktop settings from loading on Windows 11 versions 24H2 and 25H2. Backgrounds may revert to solid black, and slideshow or contrast-theme settings may also be affected.
What to do: Do not repeatedly rebuild the theme or assume the device is infected solely because the background changed. Microsoft says manually restoring the settings will not hold while the issue is present. Keep the system backed up and watch Windows Update for the promised correction.
Teams and new Outlook may fail on ARM-based PCs
On ARM-based Windows devices—including Surface Pro 11 and Surface Laptop 7—Microsoft Teams and the new Outlook may fail to open or close unexpectedly after August security updates. Microsoft says this is most likely on new or freshly imaged computers.
What to do: Open Microsoft Store, choose Downloads → Check for updates, and install Auto Super Resolution Package version 1.0.19.0 or later. Classic Outlook, Word and Excel are not known to be affected.
Memory integrity will turn on for more eligible Windows devices
Microsoft says Windows quality updates will begin enabling memory integrity on more eligible devices in October 2026. On some systems, virtualization-based security will also be enabled. Microsoft will evaluate hardware, driver compatibility and performance before enabling it; existing administrator policies and user choices remain in effect, and devices where it was previously disabled will not be changed automatically.
Why it matters: Memory integrity can block untrusted kernel-mode code and drivers, improving resistance to low-level tampering. Older drivers or specialized hardware may require compatibility testing.
Recommended decision: Businesses should inventory critical drivers and line-of-business hardware before October. Home users should allow Windows to complete its readiness checks rather than disabling the protection preemptively.
No consequential new Apple release this week
Current security versions remain unchanged
Apple’s official security-release list shows no new iPhone, iPad, Mac or Safari security release during September 1–7. The latest listed versions remain iOS and iPadOS 26.6.1, macOS 26.6.2 and Safari 26.6.1.
Recommended decision: No special migration is required this week. Confirm that automatic updates and Background Security Improvements remain enabled, particularly on devices that were not updated in August.
Ubuntu and Debian publish a concentrated set of security fixes
This is a patching week for Linux desktops and servers. Use the update mechanism supplied by the distribution instead of installing an upstream kernel manually.
Ubuntu issues new kernel fixes for supported LTS releases
On September 7, Ubuntu published kernel security updates affecting 22.04 LTS, 24.04 LTS and 26.04 LTS, including OEM kernel variants. The notices cover large groups of corrected CVEs. Separate kernel notices were also issued September 4 for older releases receiving Ubuntu Pro or extended maintenance.
What to do: Back up important systems, install all distribution-provided security updates and schedule a reboot so the patched kernel is actually running. Production servers should use a maintenance window and verify services afterward.
Ubuntu fixes OpenSSH and GnuPG vulnerabilities
Ubuntu’s OpenSSH update addresses three issues involving forwarded agent connections, concurrent remote forwarding and authorized-key tunnel restrictions. One issue could lead to denial of service or arbitrary code execution. Ubuntu says OpenSSH must be restarted after the standard system update.
A separate GnuPG update for Ubuntu 24.04 LTS and 26.04 LTS corrects a condition that could allow encrypted messages to be forged under certain circumstances.
What to do: Prioritize internet-facing SSH servers, bastion hosts and administrator workstations using agent forwarding. Install the supported packages, restart OpenSSH and test a new connection before closing an existing administrative session.
Debian patches Chromium, Firefox ESR, Thunderbird and server packages
Debian’s September 1–6 advisories include security updates for Chromium, Firefox ESR, Thunderbird, the libde265 media library, Tryton Server and OpenStack Keystone. The Keystone issues can cause authorization bypass or information disclosure.
Recommended decision: Linux users should run the full supported distribution update rather than updating only the kernel. Administrators should confirm that automated security updates include browsers and server applications, then verify whether any service restart or reboot is pending.
What Computer Technologies recommends this week
- Update and relaunch Chrome immediately on every Windows, Mac, Linux and Android device.
- Patch Ubuntu and Debian systems, restart OpenSSH where applicable and reboot into the corrected kernel.
- Check Windows 11 devices for known symptoms before spending time rebuilding backgrounds, themes or ARM-based app installations.
- Prepare for October’s Windows memory-integrity rollout by checking specialized drivers and critical business hardware.
- Create safe Gemini Workspace instructions for tone and formatting, while keeping confidential information out of persistent preferences.
Official information used for this briefing
Each development was checked against the vendor or distribution responsible for the product.
- Google Chrome Stable update — September 1, 2026
- Google Chrome Stable update — September 3, 2026
- Google Chrome for Android update — September 3, 2026
- Google Workspace Gemini custom-instructions rollout
- Microsoft Windows 11 24H2 known issues
- Microsoft Windows message center
- Apple security releases
- Ubuntu Security Notices
- Ubuntu OpenSSH security notice USN-8721-1
- Debian Security Information
Not sure whether these updates affect your business?
Computer Technologies can review your website, devices or digital workflow and help you identify the updates that deserve attention first.
Information verified through September 7, 2026. Product availability and security guidance may change after publication.