Monitor vulnerabilities like this one. Sign up free to get alerted when software you use is affected.
8.8

CVE-2026-85051: Google Chrome lets malicious page run code in sandbox

CVE-2026-85051 · published today
Summary

Versions of Google Chrome before 152.0.7977.82 can be tricked by a specially crafted web page into running code inside its security sandbox. This could let an attacker take control of the browser and potentially access sensitive information. Update Chrome to the latest version as soon as possible to protect against this risk.

What to do
  • Update google chrome to version 152.0.7977.82 or later.
Affected software
VendorProductAffected versions
google chrome < 152.0.7977.82
Original advisory text
Type confusion in Compositing in Google Chrome prior to 152.0.7977.82 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: High)
Type confusion in Compositing in Google Chrome prior to 152.0.7977.82 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: High)
Severity
8.8 High
Type
CWE-843Type Confusion
Timeline
Published3 Sep 2026
Updated3 Sep 2026
First seen3 Sep 2026
Sources
CVE-2026-85051 · MITRE
Monitor software like this
Free during beta