AI analysis
CVE-2026-85051 is a type confusion flaw (CWE-843) in the compositing component of Google Chrome, rated High severity by Chromium and 8.8 (AV:N/AC:L/PR:N/UI:R) under CVSS 3.1. It is triggered remotely when a user visits or opens a crafted HTML page, with no privileges required but user interaction needed. A successful attacker gains the ability to execute arbitrary code inside the Chrome sandbox, with high confidentiality, integrity, and availability impact within that confined context. All Chrome users running versions prior to 152.0.7977.82 are affected. Exploitation of this specific flaw has not been confirmed: there is no known public proof-of-concept, it is not in CISA KEV, and EPSS estimates only a 0.3% chance of exploitation in the next 30 days, although a related Chrome zero-day (CVE-2026-85046) has been reported exploited in the wild.
What to do: Update Chrome to version 152.0.7977.82 or later immediately (check via Settings > About Chrome, which also forces the update); enterprises should verify deployed versions through their endpoint inventory and push the update via their patch-management tooling. Until patched, avoid opening links or HTML content from untrusted sources, and note that a related Chrome zero-day is being exploited in the wild, raising urgency for prompt patching. Users of Chromium-based browsers may also want to check for equivalent updates from their vendor.
Affected
| Google Chrome | all versions prior to 152.0.7977.82 |
Estimated exposure
massbillions of users (Chrome is the world's dominant browser; only installs on versions before 152.0.7977.82 remain vulnerable) — Chrome holds roughly two-thirds of global desktop browser market share, implying billions of installations and users, most of whom will be patched quickly by Chrome's auto-update, making the vulnerable population large but shrinking daily.
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.