Monitor vulnerabilities like this one. Sign up free to get alerted when software you use is affected.
8.8

CVE-2026-85049: Google Chrome may execute malicious code from a webpage

CVE-2026-85049 · published today
Summary

A bug in Chrome's image‑handling component can let a specially crafted web page run unwanted code on your computer, bypassing Chrome's built‑in protection that isolates web content. This could allow attackers to take control of the browser session and potentially access sensitive data. Update Chrome to the latest version as soon as possible and keep automatic updates enabled.

What to do
  • Update google chrome to version 152.0.7977.82 or later.
Affected software
VendorProductAffected versions
google chrome < 152.0.7977.82
Original advisory text
Use after free in Skia in Google Chrome prior to 152.0.7977.82 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: High)
Use after free in Skia in Google Chrome prior to 152.0.7977.82 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: High)
Severity
8.8 High
Type
CWE-416Use After Free
Timeline
Published3 Sep 2026
Updated3 Sep 2026
First seen3 Sep 2026
Sources
CVE-2026-85049 · MITRE
Monitor software like this
Free during beta