CVE-2026-85049
8.8Google · Chrome
A use after free vulnerability in the Skia graphics library within Google Chrome allows remote attackers to execute arbitrary code via a crafted HTML page.
Executive summary
A critical use after free vulnerability in Google Chrome allows unauthenticated remote attackers to execute arbitrary code on affected systems via malicious web content.
Vulnerability
This is a use after free flaw (CWE-416) within the Skia graphics component. The vulnerability is triggered when an unauthenticated user visits a crafted HTML page, leading to potential arbitrary code execution within the browser sandbox.
Business impact
The ability for a remote attacker to execute arbitrary code poses a severe risk to organizational security, potentially leading to full system compromise or the installation of malicious software. With a CVSS score of 8.8, this high severity vulnerability necessitates immediate attention to prevent unauthorized access and protect sensitive user data.
Remediation
Immediate Action: Update all instances of Google Chrome to version 152.0.7977.82 or later immediately to incorporate the vendor provided security fix.
Proactive Monitoring: Monitor endpoint security logs for unusual browser crashes or unexpected process executions originating from the Chrome browser application.
Compensating Controls: While no direct workaround exists for use after free flaws, ensure that browser security features like site isolation are enabled and employ robust endpoint detection and response tools to identify anomalous activity.
Exploitation status
Public Exploit Available: Unknown
Analyst recommendation
Given the high severity of this vulnerability and the potential for arbitrary code execution, security teams must prioritize the deployment of the Chrome update across all managed workstations. Organizations should treat this as a high priority task to mitigate the risk of browser based attacks.