CVE-2026-85053

8.8

Google · Chrome

A vulnerability in Google Chrome CacheStorage allows a remote attacker to execute arbitrary code within the sandbox by enticing a user to visit a crafted HTML page.

Executive summary

A critical remote code execution vulnerability in Google Chrome allows unauthenticated attackers to compromise browser security through malicious web content.

Vulnerability

This flaw involves improper resource exposure within the CacheStorage component of the browser. An unauthenticated remote attacker can leverage this weakness via a specially crafted HTML page to execute arbitrary code inside the Chrome sandbox.

Business impact

The ability to execute code within the browser sandbox presents a severe risk to organizational data and endpoint integrity. With a CVSS score of 8.8, this vulnerability is classified as High, reflecting the potential for total compromise of the application environment, which could lead to unauthorized data exfiltration or the installation of further malicious payloads.

Remediation

Immediate Action: Update all instances of Google Chrome to version 152.0.7977.82 or later immediately to apply the vendor-supplied security patch.

Proactive Monitoring: Review web proxy logs and endpoint security telemetry for traffic patterns associated with the redirection of users to untrusted or suspicious external domains.

Compensating Controls: Ensure that browser-based security policies, such as site isolation and advanced threat protection features, are enabled to limit the potential impact of successful sandbox escapes.

Exploitation status

Public Exploit Available: No (exploit_available: false)

Analyst recommendation

Given the potential for remote code execution, this vulnerability poses a significant threat to the security of client workstations. IT teams should prioritize the deployment of the latest Chrome update across the enterprise to neutralize this risk. Failure to patch allows for a high-impact attack vector that bypasses standard browser protections.

More Google CVEs

Sources