• PoC PUBLIC
  • PATCH AVAILABLE

CVE-2026-85045: remote code execution in Google Chrome

Remote attackers can execute arbitrary code in Google Chrome's V8 engine by getting a user to load a crafted page, resulting in a sandbox escape. CVE-2026-85045 affects Chrome 152.x before the fixed build 152.0.7977.82; the vendor lists 152.0.7977.82 as the fixed version. Exploitation requires network delivery of the malicious content and user interaction to visit the crafted page.

Published Updated Source: CVE Program, NVD, FIRST EPSS

CVSS 3.1
7.5HIGH
EPSS
0.00289
CWE
CWE-367
KEV DUE DATE
Not listed
PATCH
Available

DIRAS TAKE

Urgent: public exploit code exists for this Chrome V8 race condition, so update to the fixed Chrome 152.0.7977.82 immediately or block access to vulnerable builds until patched.

What is CVE-2026-85045?

Remote attackers can execute arbitrary code in Google Chrome's V8 engine by getting a user to load a crafted page, resulting in a sandbox escape. CVE-2026-85045 affects Chrome 152.x before the fixed build 152.0.7977.82; the vendor lists 152.0.7977.82 as the fixed version. Exploitation requires network delivery of the malicious content and user interaction to visit the crafted page.

Vector CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H

Which versions of Google Chrome are affected?

BRANCHAFFECTEDFIXED
152.x152.0.7977.82 – before 152.0.7977.82152.0.7977.82

Is CVE-2026-85045 being exploited?

Public exploit code is available.

How to fix CVE-2026-85045

  1. Install the update to Chrome 152.0.7977.82 which contains the fix.
  2. If you cannot patch immediately, restrict access to vulnerable Chrome builds and block or filter untrusted web content.
  3. Monitor endpoints for signs of compromise and unusual process activity tied to Chrome.
  4. Follow Google's vendor guidance and apply security configuration hardening for browsers.

Frequently asked questions

Is CVE-2026-85045 being actively exploited?

Public exploit code is available for CVE-2026-85045, indicating active proof-of-concept capabilities.

Which Chrome versions are affected by CVE-2026-85045?

Chrome 152.x builds before 152.0.7977.82 are affected; the issue is fixed in 152.0.7977.82.

Is there a patch for CVE-2026-85045?

Yes. Google released a fix in Chrome build 152.0.7977.82.

Does CVE-2026-85045 require authentication?

No authentication is required, but the vulnerability requires a user to load a crafted web page (user interaction).

References