Register for the AI for Security Summit: Join Figma, Perplexity & Wiz

CVE-2026-85051
vulnerability analysis and mitigation

Overview

CVE-2026-85051 is a type confusion vulnerability in the Compositing component of Google Chrome that allows a remote attacker to execute arbitrary code inside the browser sandbox via a crafted HTML page. It affects all versions of Google Chrome prior to 152.0.7977.82 and was reported internally by Google on 2026-08-27. The vulnerability was publicly disclosed on September 3, 2026, alongside a stable channel update. It carries a CVSS v3.1 base score of 8.8 (High) (Chrome Releases, GitHub Advisory).

Technical details

The vulnerability is classified as CWE-843 (Access of Resource Using Incompatible Type / 'Type Confusion'), occurring within Chrome's Compositing subsystem — the component responsible for rendering and layering visual elements on screen. When processing a specially crafted HTML page, the compositing engine accesses an object or resource using a type incompatible with how it was originally allocated, enabling memory corruption that can be leveraged for arbitrary code execution. Exploitation requires user interaction (visiting a malicious page) but no authentication or special privileges. The Chromium issue tracker entry is tracked under issue 553449113 (Chrome Releases, GitHub Advisory).

Impact

Successful exploitation allows a remote attacker to execute arbitrary code within the Chrome browser sandbox, achieving high confidentiality, integrity, and availability impact on the affected browser process. While the sandbox limits direct host OS access, sandbox escape chained with this vulnerability could lead to full system compromise. All users running Google Chrome versions prior to 152.0.7977.82 on Windows, Mac, and Linux are affected (Chrome Releases, GitHub Advisory).

Exploitability

As of the disclosure date, there is no public proof-of-concept exploit or evidence of active in-the-wild exploitation specifically for CVE-2026-85051. The EPSS score is approximately 0.321–0.337%, indicating a relatively low near-term exploitation probability. Notably, a separate vulnerability in the same Chrome update (CVE-2026-85046, type confusion in V8) was confirmed by Google to have an active in-the-wild exploit, but CVE-2026-85051 was not similarly flagged. The vulnerability is not currently listed in the CISA Known Exploited Vulnerabilities catalog (Chrome Releases, GitHub Advisory).

Mitigation and workarounds

Google has released a patch in Chrome stable channel version 152.0.7977.82 (Linux) and 152.0.7977.82/.83 (Windows and Mac). Users and administrators should update Chrome immediately to this version or later. Enterprise environments should deploy the patched version via their standard update management process, and automatic updates should be enabled where possible. No configuration-based workaround is available; patching is the only remediation (Chrome Releases).

Community reactions

The September 3, 2026 Chrome update received broad coverage due to the simultaneous disclosure of CVE-2026-85046, a V8 type confusion zero-day confirmed exploited in the wild, which drew significant attention to the entire release. Security outlets including HotHardware and CyberPress reported on the update, urging users to patch immediately. The CIS issued an advisory noting multiple vulnerabilities in the release could allow arbitrary code execution. CVE-2026-85051 itself was not individually highlighted in major commentary, as attention was focused on the actively exploited CVE-2026-85046 (Chrome Releases, CIS Advisory).

Additional resources

Linux Distribution fix status

Fix availability across major Linux distributions and their releases.

Debian

Fixed

bookworm

chromium: 152.0.7977.82-1~deb12u1

Fixed

sid

chromium: 152.0.7977.82-1

Fixed

trixie

chromium: 152.0.7977.82-1~deb13u1

Fixed

SourceThis report was generated using AI

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management