Use After Free Vulnerability in Google Chrome Affects Multiple Versions
CVE-2026-85048

8.3HIGH

Key Information:

Vendor

Google

Status
Vendor
CVE Published:
3 September 2026

What is CVE-2026-85048?

A use after free vulnerability was identified in the compositing module of Google Chrome, which could allow an attacker to execute arbitrary code outside the sandbox. This could be triggered by a specially crafted HTML page, compromising the renderer process and enabling remote code execution. Users are advised to update to the latest version to mitigate this risk.

Affected Version(s)

Chrome 152.0.7977.82

References

CVSS V3.1

Score:
8.3
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
None
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.