CVE-2026-85048
8.3Google · Chrome
A use-after-free vulnerability in the Google Chrome Compositing component allows a remote attacker to achieve arbitrary code execution outside the sandbox via a crafted HTML page.
Executive summary
A critical use-after-free vulnerability in Google Chrome allows remote attackers to escape the browser sandbox and execute arbitrary code on the underlying system.
Vulnerability
The flaw is a use-after-free error (CWE-416) within the Compositing component of the browser. It requires a user to interact with a crafted HTML page, but it does not require prior authentication to trigger.
Business impact
The exploitation of this vulnerability carries a high risk, as evidenced by its CVSS score of 8.3. A successful attack allows a remote actor to bypass security sandbox protections, potentially leading to full system compromise, exfiltration of sensitive user data, or the installation of persistent malware on the host machine.
Remediation
Immediate Action: Update all Google Chrome instances to version 152.0.7977.82 or later immediately to incorporate the necessary security patches.
Proactive Monitoring: Monitor endpoint logs for suspicious browser process behavior or unexpected crashes that may indicate exploitation attempts.
Compensating Controls: Ensure that users operate with the minimum necessary privileges and utilize browser-based security policies to restrict the execution of untrusted or malicious scripts.
Exploitation status
Public Exploit Available: No
Analyst recommendation
Given the severity of potential sandbox escapes, organizations must treat this update as a high priority for all web-facing endpoints. Administrators should deploy the latest version of Chrome across the enterprise environment to ensure protection against potential exploitation of this memory-related flaw.