T
Threats
Google Chrome Critical Vulnerabilities
Overview
CVE: CVE-2026-85042, CVE-2026-85047
Severity: Critical
Date: 4 September 2026
Products: Google Chrome for Windows, macOS, Linux and iOS
Google has published security updates for two Chrome vulnerabilities that could allow a remote attacker to execute arbitrary code outside the browser sandbox through a crafted HTML page. Both vulnerabilities have a CVSS score of 9.6. Google rates CVE-2026-85042 as High severity under Chromium's internal severity system and CVE-2026-85047 as Medium.Google has published security updates for two Chrome vulnerabilities that could allow a remote attacker to execute arbitrary code outside the browser sandbox through a crafted HTML page. Both vulnerabilities have a CVSS score of 9.6. Google rates CVE-2026-85042 as High severity under Chromium's internal severity system and CVE-2026-85047 as Medium.
Affected Versions
Google Chrome for Windows, macOS and Linux
Affected: Versions before 152.0.7977.82
Fixed: Chrome 152.0.7977.82/.83 for Windows and macOS, and 152.0.7977.82 for Linux
Not affected: Google has not specified additional unaffected versions or configurations in the published advisory
Source: Google Chrome Stable Channel Update for Desktop, 3 September 2026
Google Chrome for iOS
Affected: Versions before 152.0.7977.82
Fixed: Google Chrome on iOS 152.0.7977.82 or later
Not affected: The published CVE description identifies Chrome on iOS as the affected platform. Google has not specified further unaffected configurations
Vulnerability Breakdown
CVE-2026-85042 – Use-After-Free in DevTools
Severity: Critical
CVSS: 9.6
Chromium security severity: High
Description: A use-after-free flaw in Chrome DevTools could be triggered through a crafted HTML page. The condition could allow a remote attacker to execute arbitrary code outside the Chrome sandbox.
Impact: Successful exploitation could compromise the browser process and permit code execution beyond the sandbox boundary.
Conditions: The target must process attacker-controlled web content in a vulnerable Chrome version.
CVE-2026-85047 – Improper Input Validation in Transactions Platform
Severity: Critical
CVSS: 9.6
Chromium security severity: Medium
Description: Improper input validation in the Transactions Platform component of Chrome on iOS could be triggered through a crafted HTML page. A remote attacker could potentially execute arbitrary code outside the sandbox.
Impact: Successful exploitation could enable code execution beyond the Chrome sandbox on an affected iOS device.
Conditions: The target must use a vulnerable Chrome for iOS version and process attacker-controlled web content.
Mitigation
Update Chrome on Windows and macOS to 152.0.7977.82/.83 or later.
Update Chrome on Linux to 152.0.7977.82 or later.
Update Chrome on iOS to 152.0.7977.82 or later through the Apple App Store.
Relaunch Chrome after installation so the update is applied.
Verify the installed version through Chrome > Help > About Google Chrome on desktop.
Prioritise managed, internet-facing and high-value user endpoints for verification.
Summary for IT Teams
Products: Google Chrome for Windows, macOS, Linux and iOS
Threat Level: Critical, CVSS 9.6
Action Required: Deploy the latest stable Chrome release to affected endpoints, relaunch the browser and verify that no desktop or iOS installation remains below the fixed version.
Reference
Need Help?
Secure ISS can help your organisation identify vulnerable Chrome installations, verify update deployment and prioritise remediation across managed endpoints. Call 1300 769 460 or email the Secure ISS team for assistance.

