CVE-2026-85051: Type confusion in Compositing
Chromium CVE-2026-85051: Type confusion in Compositing
Other sources
This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see Google Chrome Releases for more information.
— Microsoft
Type confusion in Compositing in Google Chrome prior to 152.0.7977.82 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: High)
— MITRE
Credit
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 152.0.7977.82 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 152.0.4191.66 - Upgrade
Upgrade
Chromium/Google Chrome (Chromium-based: Microsoft Edge)to a version that resolves this vulnerability.Fixed in 152.0.7977.82
Event History
Peer vulnerabilities
Found alongside the following vulnerabilities.
Frequently Asked Questions
What does an attacker need to exploit this issue?
The attacker needs to induce Chrome to process a crafted HTML page. The reported impact is arbitrary code execution inside the Chrome sandbox.
Which Chrome versions are affected?
Google Chrome versions prior to 152.0.7977.82 are affected. Update to 152.0.7977.82 or a later version.