ZeroHour
Organization

HKCERT

0 mentions in 7 days · 1 in 30 days · 1 total · first seen · last

Timeline

Two critical Chrome flaws put users at risk on malicious websites

Google patched 26 Chrome flaws, including two critical use-after-frees and an actively exploited V8 sandbox escape (CVE-2026-85046); update to 152.0.7977.82/.83.

Chrome's desktop update fixes 26 security issues, including critical use-after-free flaws CVE-2026-84353 in Shared Tab Groups and CVE-2026-84352 in WebGL, both allowing code execution outside the browser sandbox via crafted HTML pages. Google subsequently patched CVE-2026-85046, a high-severity V8 JavaScript engine flaw with exploits already in the wild that enables arbitrary code execution inside the Chrome sandbox; HKCERT rates the overall risk as extremely high. Fixed versions are 152.0.7977.82/.83 on Windows and Mac and 152.0.7977.82 on Linux.

Related CVEs

  • Actively Exploited V8 Type Confusion in Google Chrome (CVE-2026-85046)
    Google Chrome versions prior to 152.0.7977.82 contain a type confusion flaw (CWE-843) in the V8 JavaScript engine, which mishandles object types during engine operations (public proof-of-concept writeups indicate it is reachable through array sorting and WebAssembly-related code paths). A remote attacker triggers the flaw simply by getting a user to open a crafted HTML page, with no privileges or authentication required. Successful exploitation lets the attacker execute arbitrary code inside the browser's sandbox, and public reporting shows it being chained with Windows zero-days (the 'BlueMoon' exploit kit) by Chinese espionage groups for broader compromise. Any user of an unpatched Chrome or another build embedding the affected V8 engine is exposed. The vulnerability is a zero-day that was actively exploited in the wild before patching, was added to CISA's KEV on 2026-09-04, and has five public proof-of-concept references.
    · Google Chrome prior to 152.0.7977.82 · Google Chromium V8 V8 engine versions bundled with Chrome prior to 152.0.7977.82 KEV PoC ×5mass
  • Use-After-Free RCE in Google Chrome for Android Shared Tab Groups
    CVE-2026-84353 is a use-after-free memory-corruption flaw (CWE-416) in the Shared Tab Groups feature of Google Chrome on Android. A remote attacker can trigger it by luring a user to a crafted HTML page, relying on social engineering to get the interaction required. Successful exploitation allows arbitrary code execution outside the browser sandbox, meaning the attacker can escape Chrome's process isolation and run code with broader system privileges. Only Chrome for Android versions prior to 152.0.7977.75 are affected; desktop Chrome users are not affected by this flaw. As of now there is no known in-the-wild exploitation, no public proof-of-concept, it is not in CISA's KEV catalog, and EPSS estimates only a 0.3% chance of exploitation in the next 30 days.
    · Google Chrome for Android prior to 152.0.7977.75mass
  • Use-after-free in WebGL in Chrome for Android allows out-of-sandbox code execution
    CVE-2026-84352 is a use-after-free memory-safety flaw (CWE-416) in the WebGL component of Google Chrome on Android, rated Critical with a CVSS 3.1 score of 9.6. It is triggered when a remote attacker persuades a user to open a specially crafted HTML page in the vulnerable browser. Successful exploitation lets the attacker execute arbitrary code outside the browser's sandbox, meaning the compromise is not limited to the renderer process and could yield high-impact confidentiality, integrity, and availability loss on the device. Only Chrome on Android prior to version 152.0.7977.75 is affected per the advisory, while desktop Chrome is not listed as impacted. There is currently no known public proof-of-concept, the flaw is not in CISA's KEV catalog, and EPSS estimates only a 0.3% chance of exploitation within 30 days, though it has drawn public coverage warning users about critical Chrome flaws on malicious websites.
    · google chrome (on Android) prior to 152.0.7977.75mass

Appears with

Entities are extracted by the model from each article. Watching an entity keeps it in this browser only (no account); the watchlist page and dashboard alerts use it.