Junglewise Threat Intelligence

CVE-2026-85048: Google Chrome use after free in Compositing

CVE-2026-85048 · Severity: high · CVSS 8.3 · Published 2026-09-03

Technologies: Google Chrome. Vendors: Google.

Executive brief

Google Chrome's Compositing component contains a use-after-free vulnerability that could allow an attacker to execute arbitrary code outside the browser sandbox. An attacker who has already compromised the renderer process can exploit this flaw via a crafted HTML page, potentially gaining full control of the system. This represents a critical sandbox escape that could enable data theft, malware installation, or complete system compromise.

Technical details

A use-after-free vulnerability exists in Chrome's Compositing component (bug ID 540357382), where memory is accessed after it has been freed. The vulnerability requires the attacker to first compromise the renderer process (typically via another browser vulnerability or attack). Once the renderer is compromised, the attacker can trigger the use-after-free via a crafted HTML page, leading to arbitrary code execution outside the sandbox boundary. This is a sandbox escape condition. The vulnerability was patched in Chrome version 152.0.7977.82 released on September 3, 2026. The vulnerability does not appear to have been exploited in the wild at the time of disclosure.

Affected products

  • Google Chrome prior to 152.0.7977.82

Timeline

  • 2026-09-03: disclosed: Patched in Chrome 152.0.7977.82
  • 2026-07-29: other: Vulnerability reported by Ngoc Hieu

References

Related threats