Skip to content
GoogleCVE-2026-85049

Google Chrome: use after free

High8.8CVE-2026-85049 · Published Sep 3, 2026 · updated Sep 8, 2026

Use after free in Skia in Google Chrome prior to 152.0.7977.82 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: High)

Google advisory

Affected versions

PackageAffectedFixed in
Chrome
Product
>= 152.0.7977.82, < 152.0.7977.82152.0.7977.82
Details and references

More Google advisories

All Google
Advisory
Google Chrome: remote code execution
High8.8Sep 3
Google Chrome: out-of-bounds write
Critical9.6Sep 3
Google Chrome: type confusion
High8.8Sep 3
Google Chrome: out-of-bounds read
Low3.1Sep 3
Google Chrome: use after free
High8.3Sep 3
Google Chrome: type confusion
High8.8Sep 3

Critical advisories by email

Wednesdays: the week’s critical and high advisories in the AI and data stack, with the fixed versions. Only in weeks that have some.

Double opt-in. Unsubscribe any time.