DIRAS TAKE
Apply the vendor update to 152.0.7977.82 immediately: public exploit code exists, so this is high urgency despite any mitigations.
What is CVE-2026-85048?
A remote attacker who has compromised the renderer process can execute code outside Chrome's sandbox in Google Chrome, tracked as CVE-2026-85048. The flaw is a use-after-free in the Compositing component; affected builds are Chrome versions before 152.0.7977.82. An attacker needs control of or ability to trigger the renderer (for example by getting a user to load a crafted HTML page) to exploit the bug and achieve arbitrary code execution with high impact. The weakness is classified as CWE-416 (Use After Free).
Vector CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:H
Which versions of Google Chrome are affected?
| BRANCH | AFFECTED | FIXED |
|---|---|---|
| 152.x | 152.0.7977.82 – before 152.0.7977.82 | 152.0.7977.82 |
Is CVE-2026-85048 being exploited?
Public exploit code is available.
How to fix CVE-2026-85048
- Update Google Chrome to 152.0.7977.82 or later.
- Restart Chrome instances and any managed browsers after applying the update.
- Limit exposure by blocking untrusted web content and risky sites at the network edge where possible.
- Monitor browser crash reports and endpoint detection logs for signs of renderer compromise or exploitation attempts.
Frequently asked questions
Is CVE-2026-85048 being actively exploited?
Public exploit code for CVE-2026-85048 is available, though it is not listed on CISA's Known Exploited Vulnerabilities catalog as of the latest update.
Which Chrome versions are affected by CVE-2026-85048?
Chrome builds before 152.0.7977.82 are affected; the issue is fixed in 152.0.7977.82.
Is there a patch for CVE-2026-85048?
Yes. Google fixed the vulnerability in Chrome 152.0.7977.82; update to that build or later.
Does CVE-2026-85048 require authentication?
Exploitation requires control of or the ability to influence the renderer process, typically achieved by getting a user to load crafted content, so no prior Chrome login is required but user interaction is involved.
References
- nvd.nist.gov/vuln/detail/CVE-2026-85048
- cve.org/CVERecord?id=CVE-2026-85048
- chromereleases.googleblog.com/2026/09/stable-channel-update-for-desktop_01882797386.html
- issues.chromium.org/issues/540357382
- All Google CVEs on CVE Radar
- CVEs published in September 2026