CVE-2026-85051

8.8

Google · Chrome

A type confusion vulnerability in the Google Chrome Compositing component allows a remote attacker to execute arbitrary code via a crafted HTML page.

Executive summary

A high-severity type confusion vulnerability in Google Chrome, identified as CVE-2026-85051, permits remote code execution within the browser sandbox.

Vulnerability

This is a type confusion flaw (CWE-843) occurring within the Compositing component. A remote, unauthenticated attacker can exploit this by convincing a user to visit a specially crafted HTML page, leading to arbitrary code execution within the sandbox environment.

Business impact

The ability for a remote attacker to execute arbitrary code poses a significant risk to organizational endpoints. Successful exploitation could lead to data theft, installation of malicious software, or further movement within the internal network. Given the CVSS score of 8.8, this vulnerability is categorized as High severity and requires immediate attention to prevent potential compromise of user systems.

Remediation

Immediate Action: Update all Google Chrome instances to version 152.0.7977.82 or later to ensure the vulnerable Compositing component is patched.

Proactive Monitoring: Review browser security logs for unusual crashes or unexpected process behavior that may indicate exploitation attempts.

Compensating Controls: Ensure that browser security features, such as site isolation and sandboxing, are enabled and enforced via centralized policy management.

Exploitation status

Public Exploit Available: No

Analyst recommendation

The vulnerability represents a critical risk to browser security due to the potential for arbitrary code execution. Security teams should prioritize the deployment of the browser update across all enterprise assets to mitigate the risk of exploitation. Organizations must treat this as a high-priority update to maintain the integrity of their workstation environments.

More Google CVEs

Sources