[CIVN-2026-0452] Multiple Vulnerabilities in Google Chrome for Desktop

By Published On: September 10, 2026

—–BEGIN PGP SIGNED MESSAGE—–

Hash: SHA256


Multiple Vulnerabilities in Google Chrome for Desktop


Indian – Computer Emergency Response Team (https://www.cert-in.org.in)


Severity Rating: HIGH


Software Affected


Google Chrome versions prior to 152.0.7977.82/.83 for Windows and Mac

Google Chrome versions prior to 152.0.7977.82 for Linux

Overview


Multiple vulnerabilities have been reported in Google which could allow a remote attacker to execute arbitrary code, obtain sensitive information, bypass security restrictions or cause denial of service (DoS) conditions on the targeted system.


Target Audience:

All end-user organizations and individuals using Google Chrome for Desktop.


Risk Assessment:

High risk of unauthorized access to sensitive data, system compromise.


Impact Assessment:

Potential for remote code execution and denial of service (DoS).


Description


Google Chrome is a popular internet browser used for accessing information on the World Wide Web. It is designed for use on desktop systems including Windows, macOS and Linux.


Multiple vulnerabilities exist in Google Chrome due to Type confusion in V8, Compositing; Out of bounds read in CrashReporting; Out of bounds write in WebGL; Incomplete cleanup in Network; Use after free in Compositing, DevTools, Skia; Race condition in V8; Improper resource exposure in CacheStorage; Improper input validation in Transactions Platform and Use of released resource in Mobile.  A remote attacker could exploit these vulnerabilities by convincing a victim to open a specially crafted web request.


Successful exploitation of these vulnerabilities could allow a remote attacker to execute arbitrary code, obtain sensitive information, bypass security restrictions or cause denial of service (DoS) conditions on the targeted system.


Note: CVE-2026-85046 is being actively exploited in the wild.


Solution


Apply appropriate as mentioned by the vendor:

https://chromereleases.googleblog.com/2026/09/stable-channel-update-for-desktop_01882797386.html



Vendor Information


Google Chrome

https://chromereleases.googleblog.com/2026/09/stable-channel-update-for-desktop_01882797386.html


References


 

https://chromereleases.googleblog.com/2026/09/stable-channel-update-for-desktop_01882797386.html


CVE Name

CVE-2026-85042

CVE-2026-85043

CVE-2026-85044

CVE-2026-85045

CVE-2026-85046

CVE-2026-85047

CVE-2026-85048

CVE-2026-85049

CVE-2026-85050

CVE-2026-85051

CVE-2026-85052

CVE-2026-85053




– —


Thanks and Regards,

CERT-In


Incident Response Help Desk

e-mail: incident@cert-in.org.in

Phone: +91-11-22902657

Toll Free Number: 1800-11-4949

Toll Free Fax : 1800-11-6969

Web: http://www.cert-in.org.in

PGP Fingerprint: A768 083E 4475 5725 B81A A379 2156 C0C0 B620 D0B4

PGP Key information:

https://www.cert-in.org.in/s2cMainServlet?pageid=CONTACTUS


Postal address:

Indian Computer Emergency Response Team (CERT-In)

Ministry of Electronics and Information Technology

Government of India

Electronics Niketan

6, C.G.O. Complex

New Delhi-110 003

—–BEGIN PGP SIGNATURE—–


iQIzBAEBCAAdFiEE6r4Iam/Ey0c/KakL3jCgcSdcys8FAmqixHQACgkQ3jCgcSdc

ys+3bQ//b/OyZ0Gp5h0OaWw326At8F1kcC1NdWVsapHjkGTb1ej0APb7KRZAHPYT

3l5XN70Mq9vuJO7Vu+wYgdoQYzPhRzkbLI3bO6oYqHRse0ulNU+fN0OwMCg4E1Xf

2lAQu0gCdPgMMXS9a979qLetCutGTCG4UQ+9pYcVYjEJzsP8sjB985fST/T7JSHP

AJxj8ECZYzGgxdNPwkV6NqYB5ZVCC6YI4VpiHg5QG/4YF951HcAlHaCyC42y5Osm

kLAq+ab+ZhvmhyvfTkMrnW9Lvy2WfcpSg10mPTO/38dD1GRXe9aih6ZsQhIqeURf

JN8ZA97NmYRwqqxjJeoD+KPd16peGVdCO/8/4wln95IbRn08RjgEQ/RU3bjCJxsO

ik7hFQnzGXiA9g2/b2oGOuTn8ekYL1EPOBlTm63j49WMn11chPLWfkNZ1UrwRdor

FW2RfwQ1k2eFYjd7stEB/SY0lojOkFs+vCwXHfVeHy2kAUbmEXNY0DNMHyRk7xcK

Na9crukFJbvO8yMa1MYEBuMfExsBt51BwCpr/jx+jKs8KMjH201uUedEp5JHcEu6

VGB0lZ/Z+e4F7z+t80cGWn8FROhRFbKIZ8OPP8L2R+aYyz1qZ1AqqS/4rJq9e8Os

3FcUFeUQtkEWEmjzgkzK+hWLMomp8lCPYfXWZmaWCRzoSoZln/I=

=oFi6

—–END PGP SIGNATURE—–

Share this article