Critical Vulnerabilities in Google Chrome Expose Users to Remote Code Execution

Critical Vulnerabilities in Google Chrome Expose Users to Remote Code Execution

First seen 4 Sep 2026, 02:44 UTC CisecurityHkcertcve.mitre.org 72.9

Article Content

Browse articles
ThreatCluster

Multiple vulnerabilities have been identified in Google Chrome, with the most severe allowing for arbitrary code execution. CVE-2026-85046 is currently being exploited in the wild, posing an extremely high risk to users. Affected versions include Google Chrome prior to 152.0.7977.82 for Linux and 152.0.7977.82/.83 for Mac and Windows. The vulnerabilities include issues such as improper authorization, use-after-free errors, and buffer overflows, which could lead to denial of service and privilege escalation. Users are advised to update to the latest version immediately to mitigate risks. The vulnerabilities were published on September 1, 2026, with active exploitation confirmed for CVE-2026-85046 on September 3, 2026. The situation remains critical as attackers could gain significant control over affected systems.

Key Points: • CVE-2026-85046 is actively exploited, allowing remote code execution. • Users should update Google Chrome to version 152.0.7977.82 or later immediately. • Multiple vulnerabilities could lead to severe impacts, including privilege escalation and data disclosure.

Ask AI about this cluster

Timeline

2026-09-01
Multiple Chrome vulnerabilities disclosed
Google Chrome vulnerabilities were published, including CVEs for use-after-free and improper authorization issues.
Cisecurity
2026-09-01
CVE-2026-84334 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE
2026-09-01
CVE-2026-84328 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE
2026-09-01
CVE-2026-84323 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE
2026-09-01
CVE-2026-84330 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE
2026-09-01
CVE-2026-84357 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE
2026-09-01
CVE-2026-84351 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE
2026-09-01
CVE-2026-84324 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE
2026-09-01
CVE-2026-84333 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE
2026-09-01
CVE-2026-84327 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE