ZeroHour

CVE-2026-85044

mass

Same-Origin Policy Bypass via Released-Resource Bug in Google Chrome for Android

CVSS 3.1
6.5 medium
EPSS
<1%p14
Published
()
Modified
AI analysis

CVE-2026-85044 is a use-of-released-resource flaw (CWE-672) in the mobile-specific code of Google Chrome on Android, rated Medium (CVSS 6.5) with an integrity-only impact. A remote attacker must use social engineering to persuade a user to open a crafted HTML page, after which the bug allows the web origin (same-origin) policy to be bypassed. A successful attacker can act across origin boundaries in the affected browsing session; the CVSS vector indicates no direct confidentiality or availability loss. Only Chrome for Android builds prior to 152.0.7977.82 are affected; desktop Chrome and other browsers are not named in the advisory. No public proof-of-concept, KEV listing, or confirmed exploitation exists for this CVE (EPSS 0.2%), although a related Chrome zero-day (CVE-2026-85046) is reported exploited in the wild.

What to do: Update Chrome on Android to 152.0.7977.82 or later via the Google Play Store (Settings > About Chrome) on all managed and BYOD devices. Since the flaw requires social engineering and user interaction, reinforce user caution with unsolicited links; desktop Chrome is not listed as affected by this CVE. Monitor Chrome releases closely, as a related Chrome zero-day (CVE-2026-85046) is being actively exploited.

Affected
Google Chrome (for Android)all versions prior to 152.0.7977.82
Estimated exposure
massbillions of users (Chrome for Android has 10B+ cumulative Google Play installs and is the default browser on roughly 3B+ active Android devices) — Chrome is the default browser on Android with cumulative Play installs in the billions, so effectively all Android users running pre-152.0.7977.82 Chrome builds are plausibly exposed, though actual exploitation requires user interaction…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Use of released resource in Mobile in Google Chrome on on Android prior to 152.0.7977.82 allowed a remote attacker leveraging social engineering to bypass web origin policy via a crafted HTML page. (Chromium security severity: Medium)

Vendors
google
Products
chrome
Weakness
CWE-672
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N

In the news

Google Chrome Zero-day Vulnerability Exploited in the Wild (CVE-2026-85046)

Google patched 12 Chrome flaws including in-the-wild V8 zero-day CVE-2026-85046; CISA added it to the KEV catalog.

Google released Chrome 152.0.7977.82/.83 for Windows and Mac (152.0.7977.82 for Linux) fixing 12 vulnerabilities, including CVE-2026-85046, a type confusion flaw in the V8 JavaScript engine being exploited in the wild. CISA added CVE-2026-85046 to its Known Exploited Vulnerabilities Catalog with a patch deadline of September 18, 2026. This is Chrome's sixth zero-day patched in 2026, following CVE-2026-2441, CVE-2026-3909, CVE-2026-3910, CVE-2026-5281 and CVE-2026-11645. The other 11 fixes include use-after-free, out-of-bounds, race condition and input validation flaws in Skia, WebGL, DevTools, Network, Compositing and other components.