T

Threats

Google Chrome Critical Vulnerabilities

Overview

Google has published security updates for two Chrome vulnerabilities that could allow a remote attacker to execute arbitrary code outside the browser sandbox through a crafted HTML page. Both vulnerabilities have a CVSS score of 9.6. Google rates CVE-2026-85042 as High severity under Chromium's internal severity system and CVE-2026-85047 as Medium.Google has published security updates for two Chrome vulnerabilities that could allow a remote attacker to execute arbitrary code outside the browser sandbox through a crafted HTML page. Both vulnerabilities have a CVSS score of 9.6. Google rates CVE-2026-85042 as High severity under Chromium's internal severity system and CVE-2026-85047 as Medium.


Affected Versions

Google Chrome for Windows, macOS and Linux

Google Chrome for iOS

  • Affected: Versions before 152.0.7977.82

  • Fixed: Google Chrome on iOS 152.0.7977.82 or later

  • Not affected: The published CVE description identifies Chrome on iOS as the affected platform. Google has not specified further unaffected configurations

  • Source: Google Chromium issue for CVE-2026-85047


Vulnerability Breakdown

CVE-2026-85042 – Use-After-Free in DevTools

  • Severity: Critical

  • CVSS: 9.6

  • Chromium security severity: High

  • Description: A use-after-free flaw in Chrome DevTools could be triggered through a crafted HTML page. The condition could allow a remote attacker to execute arbitrary code outside the Chrome sandbox.

  • Impact: Successful exploitation could compromise the browser process and permit code execution beyond the sandbox boundary.

  • Conditions: The target must process attacker-controlled web content in a vulnerable Chrome version.

  • Source: Google Chromium issue for CVE-2026-85042

CVE-2026-85047 – Improper Input Validation in Transactions Platform

  • Severity: Critical

  • CVSS: 9.6

  • Chromium security severity: Medium

  • Description: Improper input validation in the Transactions Platform component of Chrome on iOS could be triggered through a crafted HTML page. A remote attacker could potentially execute arbitrary code outside the sandbox.

  • Impact: Successful exploitation could enable code execution beyond the Chrome sandbox on an affected iOS device.

  • Conditions: The target must use a vulnerable Chrome for iOS version and process attacker-controlled web content.

  • Source: Google Chromium issue for CVE-2026-85047


Mitigation

  • Update Chrome on Windows and macOS to 152.0.7977.82/.83 or later.

  • Update Chrome on Linux to 152.0.7977.82 or later.

  • Update Chrome on iOS to 152.0.7977.82 or later through the Apple App Store.

  • Relaunch Chrome after installation so the update is applied.

  • Verify the installed version through Chrome > Help > About Google Chrome on desktop.

  • Prioritise managed, internet-facing and high-value user endpoints for verification.


Summary for IT Teams

  • Products: Google Chrome for Windows, macOS, Linux and iOS

  • Threat Level: Critical, CVSS 9.6

  • Action Required: Deploy the latest stable Chrome release to affected endpoints, relaunch the browser and verify that no desktop or iOS installation remains below the fixed version.


Reference


Need Help?

Secure ISS can help your organisation identify vulnerable Chrome installations, verify update deployment and prioritise remediation across managed endpoints. Call 1300 769 460 or email the Secure ISS team for assistance.

Cta Image

Australia is secure when
Australian talent defends it.

Reach out today to discuss how with Lumara, we can work together to protect your business from the always changing Australian threat landscape.

Cta Image

Australia is secure when
Australian talent defends it.

Reach out today to discuss how with Lumara, we can work together to protect your business from the always changing Australian threat landscape.

Cta Image

Australia is secure when
Australian talent defends it.

Reach out today to discuss how with Lumara, we can work together to protect your business from the always changing Australian threat landscape.