
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-85049 is a use-after-free vulnerability in the Skia graphics rendering engine within Google Chrome, allowing a remote attacker to execute arbitrary code inside the Chrome sandbox via a crafted HTML page. It was reported by Google on August 27, 2026, and publicly disclosed on September 3, 2026, alongside the release of Chrome 152.0.7977.82. All versions of Google Chrome prior to 152.0.7977.82 are affected across Windows, Mac, and Linux platforms. The vulnerability carries a CVSS v3.1 base score of 8.8 (High) (Chrome Releases, GitHub Advisory).
The vulnerability is classified as CWE-416 (Use After Free) and CWE-825 (Expired Pointer Dereference), rooted in improper memory management within Chrome's Skia 2D graphics library. When Chrome processes a specially crafted HTML page, the Skia rendering engine can be triggered to access memory that has already been freed, leading to a corrupted memory state that an attacker can leverage to redirect execution flow. Exploitation requires user interaction — specifically, a victim visiting a malicious web page — but no authentication or elevated privileges are needed. The bug was tracked internally as Chromium issue 553345874 and was discovered by Google's own security team (Chrome Releases, GitHub Advisory).
Successful exploitation allows a remote attacker to execute arbitrary code within the Chrome sandbox, compromising confidentiality, integrity, and availability of the browser process. While the sandbox limits direct access to the underlying operating system, code execution within the sandbox can serve as a stepping stone for sandbox escape when chained with additional vulnerabilities. Sensitive data accessible within the browser context — including session tokens, credentials, and browsing history — may be exposed (Chrome Releases, GitHub Advisory).
As of the disclosure date, there is no public proof-of-concept exploit and no evidence of active in-the-wild exploitation specifically for CVE-2026-85049. Notably, the same Chrome update (152.0.7977.82) addresses CVE-2026-85046 (V8 type confusion), for which Google confirmed an in-the-wild exploit exists, but CVE-2026-85049 is not listed as actively exploited. The EPSS score is approximately 0.31%, placing it in the 22nd percentile for exploitation likelihood. The vulnerability is not currently listed in the CISA Known Exploited Vulnerabilities (KEV) catalog (Chrome Releases, GitHub Advisory).
Google has patched this vulnerability in Chrome 152.0.7977.82 (Linux) and 152.0.7977.82/.83 (Windows and Mac), released on September 3, 2026. Users should update Chrome immediately via the browser's built-in update mechanism (Settings → Help → About Google Chrome) or enable automatic updates. As a precautionary measure, users should avoid visiting untrusted or suspicious websites until the update is applied. Enterprise administrators should prioritize deployment of the patched version across managed endpoints (Chrome Releases, Microsoft MSRC).
The September 3, 2026 Chrome update received broad coverage due to the simultaneous disclosure of CVE-2026-85046, a V8 type confusion zero-day confirmed as actively exploited in the wild, which drew significant attention to the entire patch batch including CVE-2026-85049. Security outlets such as HotHardware and IT-Connect reported on the update urging users to patch immediately, framing it in the context of Chrome's sixth zero-day of 2026. CIS issued an advisory noting multiple vulnerabilities in the update could allow arbitrary code execution. CVE-2026-85049 itself did not attract separate notable researcher commentary beyond its inclusion in the broader update coverage (Chrome Releases).
Fix availability across major Linux distributions and their releases.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."