ZeroHour

CVE-2026-85051

mass

Type Confusion in Google Chrome Compositing Allows In-Sandbox Code Execution

CVSS 3.1
8.8 high
EPSS
<1%p25
Published
()
Modified
AI analysis

CVE-2026-85051 is a type confusion flaw (CWE-843) in the compositing component of Google Chrome, rated High severity by Chromium and 8.8 (AV:N/AC:L/PR:N/UI:R) under CVSS 3.1. It is triggered remotely when a user visits or opens a crafted HTML page, with no privileges required but user interaction needed. A successful attacker gains the ability to execute arbitrary code inside the Chrome sandbox, with high confidentiality, integrity, and availability impact within that confined context. All Chrome users running versions prior to 152.0.7977.82 are affected. Exploitation of this specific flaw has not been confirmed: there is no known public proof-of-concept, it is not in CISA KEV, and EPSS estimates only a 0.3% chance of exploitation in the next 30 days, although a related Chrome zero-day (CVE-2026-85046) has been reported exploited in the wild.

What to do: Update Chrome to version 152.0.7977.82 or later immediately (check via Settings > About Chrome, which also forces the update); enterprises should verify deployed versions through their endpoint inventory and push the update via their patch-management tooling. Until patched, avoid opening links or HTML content from untrusted sources, and note that a related Chrome zero-day is being exploited in the wild, raising urgency for prompt patching. Users of Chromium-based browsers may also want to check for equivalent updates from their vendor.

Affected
Google Chromeall versions prior to 152.0.7977.82
Estimated exposure
massbillions of users (Chrome is the world's dominant browser; only installs on versions before 152.0.7977.82 remain vulnerable) — Chrome holds roughly two-thirds of global desktop browser market share, implying billions of installations and users, most of whom will be patched quickly by Chrome's auto-update, making the vulnerable population large but shrinking daily.

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Type confusion in Compositing in Google Chrome prior to 152.0.7977.82 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: High)

Vendors
google
Products
chrome
Weakness
CWE-843
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

In the news

Google Chrome Zero-day Vulnerability Exploited in the Wild (CVE-2026-85046)

Google patched 12 Chrome flaws including in-the-wild V8 zero-day CVE-2026-85046; CISA added it to the KEV catalog.

Google released Chrome 152.0.7977.82/.83 for Windows and Mac (152.0.7977.82 for Linux) fixing 12 vulnerabilities, including CVE-2026-85046, a type confusion flaw in the V8 JavaScript engine being exploited in the wild. CISA added CVE-2026-85046 to its Known Exploited Vulnerabilities Catalog with a patch deadline of September 18, 2026. This is Chrome's sixth zero-day patched in 2026, following CVE-2026-2441, CVE-2026-3909, CVE-2026-3910, CVE-2026-5281 and CVE-2026-11645. The other 11 fixes include use-after-free, out-of-bounds, race condition and input validation flaws in Skia, WebGL, DevTools, Network, Compositing and other components.