CVE-2026-85051
8.8Google · Chrome
A type confusion vulnerability in the Google Chrome Compositing component allows a remote attacker to execute arbitrary code via a crafted HTML page.
Executive summary
A high-severity type confusion vulnerability in Google Chrome, identified as CVE-2026-85051, permits remote code execution within the browser sandbox.
Vulnerability
This is a type confusion flaw (CWE-843) occurring within the Compositing component. A remote, unauthenticated attacker can exploit this by convincing a user to visit a specially crafted HTML page, leading to arbitrary code execution within the sandbox environment.
Business impact
The ability for a remote attacker to execute arbitrary code poses a significant risk to organizational endpoints. Successful exploitation could lead to data theft, installation of malicious software, or further movement within the internal network. Given the CVSS score of 8.8, this vulnerability is categorized as High severity and requires immediate attention to prevent potential compromise of user systems.
Remediation
Immediate Action: Update all Google Chrome instances to version 152.0.7977.82 or later to ensure the vulnerable Compositing component is patched.
Proactive Monitoring: Review browser security logs for unusual crashes or unexpected process behavior that may indicate exploitation attempts.
Compensating Controls: Ensure that browser security features, such as site isolation and sandboxing, are enabled and enforced via centralized policy management.
Exploitation status
Public Exploit Available: No
Analyst recommendation
The vulnerability represents a critical risk to browser security due to the potential for arbitrary code execution. Security teams should prioritize the deployment of the browser update across all enterprise assets to mitigate the risk of exploitation. Organizations must treat this as a high-priority update to maintain the integrity of their workstation environments.