CVE-2026-85049
Ein entfernter, anonymer Angreifer kann mehrere Schwachstellen in Google Chrome / Microsoft Edge ausnutzen, um beliebigen Programmcode auszuführen, um Informationen offenzulegen und um Sicherheitsmechanismen zu umgehen.
CSIRTS triage
- What
- Multiple vulnerabilities in Chrome allow remote code execution, information disclosure, and security mechanism bypass.
- Who is affected
- All Chrome browser users, particularly those visiting untrusted websites or receiving socially engineered content.
- Urgency
- Critical priority because remote code execution in a web browser is widely exploitable and frequently targeted; high-severity browser compromise affects all web-accessible user data and system access.
- Action
- Update Chrome to the latest version immediately; enable automatic updates if not already enabled.
AI-assisted analysis generated from the source advisory — verify against the original.
⚡ Watch CVE-2026-85049
Get an email if CVE-2026-85049 is added to CISA KEV, gains public exploit code, or a new advisory cites it — max one per day, one-click unsubscribe.
Exploitation outlook
- Low exploitation risk0.31% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 23% of all EPSS-scored CVEs.
Advisory coverage (4)
- highexploited[UPDATE] [hoch] Google Chrome / Microsoft Edge: Mehrere Schwachstellencert-bund · 2026-09-09
- unknownexploitedDSA-6484-1 chromium - security updatedebian · 2026-09-05
- unknownexploitedGoogle Chrome Multiple Vulnerabilitieshkcert · 2026-09-04
- highCVE-2026-85049: Use after free in Skia in Google Chrome prior to 152.0.7977.82 allowed a remote attacker to ex…nvd · 2026-09-03
External references
Embed the live status
— this badge updates automatically when the KEV or exploit status changes. How to embed it →
[](https://www.csirts.com/cve/CVE-2026-85049)