
[CIVN-2026-0452] Multiple Vulnerabilities in Google Chrome for Desktop
—–BEGIN PGP SIGNED MESSAGE—–
Hash: SHA256
Multiple Vulnerabilities in Google Chrome for Desktop
Indian – Computer Emergency Response Team (https://www.cert-in.org.in)
Severity Rating: HIGH
Software Affected
Google Chrome versions prior to 152.0.7977.82/.83 for Windows and Mac
Google Chrome versions prior to 152.0.7977.82 for Linux
Overview
Multiple vulnerabilities have been reported in Google which could allow a remote attacker to execute arbitrary code, obtain sensitive information, bypass security restrictions or cause denial of service (DoS) conditions on the targeted system.
Target Audience:
All end-user organizations and individuals using Google Chrome for Desktop.
Risk Assessment:
High risk of unauthorized access to sensitive data, system compromise.
Impact Assessment:
Potential for remote code execution and denial of service (DoS).
Description
Google Chrome is a popular internet browser used for accessing information on the World Wide Web. It is designed for use on desktop systems including Windows, macOS and Linux.
Multiple vulnerabilities exist in Google Chrome due to Type confusion in V8, Compositing; Out of bounds read in CrashReporting; Out of bounds write in WebGL; Incomplete cleanup in Network; Use after free in Compositing, DevTools, Skia; Race condition in V8; Improper resource exposure in CacheStorage; Improper input validation in Transactions Platform and Use of released resource in Mobile. A remote attacker could exploit these vulnerabilities by convincing a victim to open a specially crafted web request.
Successful exploitation of these vulnerabilities could allow a remote attacker to execute arbitrary code, obtain sensitive information, bypass security restrictions or cause denial of service (DoS) conditions on the targeted system.
Note: CVE-2026-85046 is being actively exploited in the wild.
Solution
Apply appropriate as mentioned by the vendor:
https://chromereleases.googleblog.com/2026/09/stable-channel-update-for-desktop_01882797386.html
Vendor Information
Google Chrome
https://chromereleases.googleblog.com/2026/09/stable-channel-update-for-desktop_01882797386.html
References
https://chromereleases.googleblog.com/2026/09/stable-channel-update-for-desktop_01882797386.html
CVE Name
CVE-2026-85042
CVE-2026-85043
CVE-2026-85044
CVE-2026-85045
CVE-2026-85046
CVE-2026-85047
CVE-2026-85048
CVE-2026-85049
CVE-2026-85050
CVE-2026-85051
CVE-2026-85052
CVE-2026-85053
– —
Thanks and Regards,
CERT-In
Incident Response Help Desk
e-mail: incident@cert-in.org.in
Phone: +91-11-22902657
Toll Free Number: 1800-11-4949
Toll Free Fax : 1800-11-6969
Web: http://www.cert-in.org.in
PGP Fingerprint: A768 083E 4475 5725 B81A A379 2156 C0C0 B620 D0B4
PGP Key information:
https://www.cert-in.org.in/s2cMainServlet?pageid=CONTACTUS
Postal address:
Indian Computer Emergency Response Team (CERT-In)
Ministry of Electronics and Information Technology
Government of India
Electronics Niketan
6, C.G.O. Complex
New Delhi-110 003
—–BEGIN PGP SIGNATURE—–
iQIzBAEBCAAdFiEE6r4Iam/Ey0c/KakL3jCgcSdcys8FAmqixHQACgkQ3jCgcSdc
ys+3bQ//b/OyZ0Gp5h0OaWw326At8F1kcC1NdWVsapHjkGTb1ej0APb7KRZAHPYT
3l5XN70Mq9vuJO7Vu+wYgdoQYzPhRzkbLI3bO6oYqHRse0ulNU+fN0OwMCg4E1Xf
2lAQu0gCdPgMMXS9a979qLetCutGTCG4UQ+9pYcVYjEJzsP8sjB985fST/T7JSHP
AJxj8ECZYzGgxdNPwkV6NqYB5ZVCC6YI4VpiHg5QG/4YF951HcAlHaCyC42y5Osm
kLAq+ab+ZhvmhyvfTkMrnW9Lvy2WfcpSg10mPTO/38dD1GRXe9aih6ZsQhIqeURf
JN8ZA97NmYRwqqxjJeoD+KPd16peGVdCO/8/4wln95IbRn08RjgEQ/RU3bjCJxsO
ik7hFQnzGXiA9g2/b2oGOuTn8ekYL1EPOBlTm63j49WMn11chPLWfkNZ1UrwRdor
FW2RfwQ1k2eFYjd7stEB/SY0lojOkFs+vCwXHfVeHy2kAUbmEXNY0DNMHyRk7xcK
Na9crukFJbvO8yMa1MYEBuMfExsBt51BwCpr/jx+jKs8KMjH201uUedEp5JHcEu6
VGB0lZ/Z+e4F7z+t80cGWn8FROhRFbKIZ8OPP8L2R+aYyz1qZ1AqqS/4rJq9e8Os
3FcUFeUQtkEWEmjzgkzK+hWLMomp8lCPYfXWZmaWCRzoSoZln/I=
=oFi6
—–END PGP SIGNATURE—–


