CVE-2026-85049: Use after free in Skia
Chromium CVE-2026-85049: Use after free in Skia
Other sources
This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see Google Chrome Releases for more information.
— Microsoft
Use after free in Skia in Google Chrome prior to 152.0.7977.82 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: High)
— MITRE
Credit
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 152.0.7977.82 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 152.0.4191.66 - Upgrade
Upgrade
Google Chrome / Chromium (Skia)to a version that resolves this vulnerability.Fixed in 152.0.7977.82
Event History
Peer vulnerabilities
Found alongside the following vulnerabilities.
Frequently Asked Questions
What must an attacker do to exploit this vulnerability?
The attacker must cause a victim to load a crafted HTML page. Successful exploitation allows arbitrary code execution inside the Chrome sandbox.
Which Chrome versions are affected?
Google Chrome versions prior to 152.0.7977.82 are affected.