CVE-2026-85045: Race Condition
Published Sep 3, 2026
·Updated
Race condition in V8 in Google Chrome prior to 152.0.7977.82 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: High)
Affected Software
2 affected components
Google Chrome<152.0.7977.82
v8<152.0.7977.82
Event History
Sep 3, 2026
CVE Published
via MITRE·07:26 PM
Data Sourced
via MITRE·07:26 PM
DescriptionWeakness
Frequently Asked Questions
1
Who is exposed to this issue?
Users of Google Chrome versions earlier than 152.0.7977.82 are exposed if they can be induced to load a crafted HTML page. The described code execution is inside the Chrome sandbox.
2
What does an attacker need to exploit it?
The attacker needs to deliver or cause the target to open a crafted HTML page remotely. No additional prerequisites or authentication requirements are stated.
3
How can I determine whether a system is affected?
Check the installed Google Chrome version. Versions prior to 152.0.7977.82 are affected according to the available information.