CVE-2026-85045: Race Condition
Chromium CVE-2026-85045: Race condition in V8
Other sources
Race condition in V8 in Google Chrome prior to 152.0.7977.82 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: High)
— MITRE
This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see Google Chrome Releases for more information.
— Microsoft
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 152.0.4191.66 - Upgrade
Upgrade
Microsoft Edge (Chromium-based)to a version that resolves this vulnerability.Fixed in 152.0.7977.82 - Upgrade
Upgrade
Google Chrometo a version that resolves this vulnerability.Fixed in 152.0.7977.82
Event History
Frequently Asked Questions
Who is exposed to this issue?
Users of Google Chrome versions earlier than 152.0.7977.82 are exposed if they can be induced to load a crafted HTML page. The described code execution is inside the Chrome sandbox.
What does an attacker need to exploit it?
The attacker needs to deliver or cause the target to open a crafted HTML page remotely. No additional prerequisites or authentication requirements are stated.
How can I determine whether a system is affected?
Check the installed Google Chrome version. Versions prior to 152.0.7977.82 are affected according to the available information.