Monitor vulnerabilities like this one. Sign up free to get alerted when software you use is affected.
8.3

CVE-2026-85048: Google Chrome before 152.0.7977.82 could let attackers run code

CVE-2026-85048 · published today
Summary

Versions of Google Chrome earlier than 152.0.7977.82 can be tricked by a specially crafted web page to run code on the computer, bypassing the browser’s normal safety barriers. This means an attacker who gets the browser to load such a page could gain control of the system. Upgrade Chrome to the latest version as soon as possible to remove the risk.

What to do
  • Update google chrome to version 152.0.7977.82 or later.
Affected software
VendorProductAffected versions
google chrome < 152.0.7977.82
Original advisory text
Use after free in Compositing in Google Chrome prior to 152.0.7977.82 allowed a remote attacker who had compromised the renderer process to execute arbitrary code outside the sandbox via a crafted ...
Use after free in Compositing in Google Chrome prior to 152.0.7977.82 allowed a remote attacker who had compromised the renderer process to execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: High)
Severity
8.3 High
Type
CWE-416Use After Free
Timeline
Published3 Sep 2026
Updated3 Sep 2026
First seen3 Sep 2026
Sources
CVE-2026-85048 · MITRE
Monitor software like this
Free during beta