Junglewise Threat Intelligence

CVE-2026-85051: Google Chrome type confusion in Compositing

CVE-2026-85051 · Severity: high · CVSS 8.8 · Published 2026-09-03

Technologies: Google Chrome. Vendors: Google.

Executive brief

Google Chrome's Compositing component contains a type confusion vulnerability that could allow an attacker to execute arbitrary code within the browser's sandbox by serving a specially crafted webpage. This could lead to data theft, malware installation, or system compromise, though the sandbox limits direct system-level damage.

Technical details

A type confusion flaw exists in the Compositing component of Google Chrome prior to version 152.0.7977.82. The vulnerability allows a remote attacker to achieve arbitrary code execution within the browser's sandbox by crafting a malicious HTML page. The attack is triggered through user interaction with the malicious webpage over the network; no authentication or elevated privileges are required. While execution occurs within the sandbox, the vulnerability could still be leveraged for further exploitation or data exfiltration. The fix is available in Chrome 152.0.7977.82 and later versions.

Affected products

  • Google Chrome prior to 152.0.7977.82

Timeline

  • 2026-09-03: disclosed
  • 2026-09-03: patched: Chrome 152.0.7977.82 released

References

Related threats