• PoC PUBLIC
  • PATCH AVAILABLE

CVE-2026-85048: use-after-free in Google Chrome

A remote attacker who has compromised the renderer process can execute code outside Chrome's sandbox in Google Chrome, tracked as CVE-2026-85048. The flaw is a use-after-free in the Compositing component; affected builds are Chrome versions before 152.0.7977.82. An attacker needs control of or ability to trigger the renderer (for example by getting a user to load a crafted HTML page) to exploit the bug and achieve arbitrary code execution with high impact.

Published Updated Source: CVE Program, NVD, FIRST EPSS

CVSS 3.1
8.3HIGH
EPSS
0.00404
CWE
CWE-416
KEV DUE DATE
Not listed
PATCH
Available

DIRAS TAKE

Apply the vendor update to 152.0.7977.82 immediately: public exploit code exists, so this is high urgency despite any mitigations.

What is CVE-2026-85048?

A remote attacker who has compromised the renderer process can execute code outside Chrome's sandbox in Google Chrome, tracked as CVE-2026-85048. The flaw is a use-after-free in the Compositing component; affected builds are Chrome versions before 152.0.7977.82. An attacker needs control of or ability to trigger the renderer (for example by getting a user to load a crafted HTML page) to exploit the bug and achieve arbitrary code execution with high impact. The weakness is classified as CWE-416 (Use After Free).

Vector CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:H

Which versions of Google Chrome are affected?

BRANCHAFFECTEDFIXED
152.x152.0.7977.82 – before 152.0.7977.82152.0.7977.82

Is CVE-2026-85048 being exploited?

Public exploit code is available.

How to fix CVE-2026-85048

  1. Update Google Chrome to 152.0.7977.82 or later.
  2. Restart Chrome instances and any managed browsers after applying the update.
  3. Limit exposure by blocking untrusted web content and risky sites at the network edge where possible.
  4. Monitor browser crash reports and endpoint detection logs for signs of renderer compromise or exploitation attempts.

Frequently asked questions

Is CVE-2026-85048 being actively exploited?

Public exploit code for CVE-2026-85048 is available, though it is not listed on CISA's Known Exploited Vulnerabilities catalog as of the latest update.

Which Chrome versions are affected by CVE-2026-85048?

Chrome builds before 152.0.7977.82 are affected; the issue is fixed in 152.0.7977.82.

Is there a patch for CVE-2026-85048?

Yes. Google fixed the vulnerability in Chrome 152.0.7977.82; update to that build or later.

Does CVE-2026-85048 require authentication?

Exploitation requires control of or the ability to influence the renderer process, typically achieved by getting a user to load crafted content, so no prior Chrome login is required but user interaction is involved.

References