Executive brief
Google Chrome's CacheStorage component contained a resource exposure vulnerability that allowed attackers to execute arbitrary code within the browser's sandbox via a malicious HTML page. This could enable attackers to compromise user data, install malware, or perform other malicious actions while evading browser security restrictions.
Technical details
CVE-2026-85053 is an improper resource exposure vulnerability in the CacheStorage component of Google Chrome. The vulnerability allows a remote attacker to execute arbitrary code inside the sandbox by crafting a malicious HTML page. No special authentication or user interaction beyond visiting a compromised page is required. The issue was patched in Chrome version 152.0.7977.82 and later. The Chromium security team rated this as High severity.
Affected products
- Google Chrome prior to 152.0.7977.82
Timeline
- 2026-09-03: disclosed
- 2026-09-03: patched: Chrome 152.0.7977.82 released