CVE-2026-85053: Improper resource exposure in CacheStorage
Chromium CVE-2026-85053: Improper resource exposure in CacheStorage
Other sources
Improper resource exposure in CacheStorage in Google Chrome prior to 152.0.7977.82 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: High)
— MITRE
This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see Google Chrome Releases for more information.
— Microsoft
Credit
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 152.0.7977.82 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 152.0.4191.66
Event History
Peer vulnerabilities
Found alongside the following vulnerabilities.
Frequently Asked Questions
What must an attacker do to exploit this issue?
The attacker must induce a user to load a crafted HTML page. Successful exploitation allows arbitrary code execution inside the Chrome sandbox.
Which Chrome versions are affected?
Google Chrome versions prior to 152.0.7977.82 are affected. Chrome 152.0.7977.82 is identified as the version boundary in the available data.