Google Chrome Multiple Vulnerabilities
Actively exploited. At least one CVE in this advisory is listed in the CISA Known Exploited Vulnerabilities catalog — exploitation has been observed in the wild. Treat remediation as urgent.
CSIRTS triage
- What
- Google Chrome contains multiple unspecified vulnerabilities.
- Who is affected
- Unknown versions of Google Chrome are affected.
- Urgency
- Severity and exploitability are unknown; remediation priority cannot be determined without additional details.
- Action
- Monitor Google Chrome security advisories for affected versions and apply patches when available.
AI-assisted analysis generated from the source advisory — verify against the original.
⚡ Watch Chrome
Get an email when a new Chrome advisory drops — max one per day, one-click unsubscribe.
Details
Original advisory: https://www.hkcert.org/security-bulletin/google-chrome-multiple-vulnerabilities_20260904
Exploitation outlook
EPSS (FIRST.org) estimates each CVE’s probability of exploitation in the next 30 days — here is the CSIRTS.com read on those numbers.
- Exploitation confirmedCVE-2026-85046Already exploited in the wild (CISA KEV) — the prediction phase is over. Patch now. Riskier than 65% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-850420.34% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 27% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-850430.32% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 25% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-850440.26% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 18% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-850450.24% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 15% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-850470.34% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 27% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-850480.33% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 25% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-850490.31% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 23% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-850500.34% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 27% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-850510.34% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 27% of all EPSS-scored CVEs.
Referenced CVEs
| CVE | CSIRTS overview | External |
|---|---|---|
| CVE-2026-85046 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-85042 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-85043 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-85044 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-85045 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-85047 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-85048 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-85049 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-85050 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-85051 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-85052 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-85053 | coverage & exploitation status | NVD · CVE.org |
Same CVEs, other sources
How other CERTs, PSIRTs and databases cover the vulnerabilities in this advisory.
- highexploited[UPDATE] [hoch] Google Chrome / Microsoft Edge: Mehrere Schwachstellencert-bund
- unknownexploitedCVE-2026-85046: Chromium: CVE-2026-85046 Type confusion in V8msrc
- unknownexploitedDSA-6484-1 chromium - security updatedebian
- unknownexploitedGoogle security advisory (AV26-883) – Update 1cccs
- unknownexploitedNCSC-2026-0341 [1.00] [M/H] Kwetsbaarheden verholpen in Google Chromencsc-nl
- highexploitedCISA Adds One Known Exploited Vulnerability to Catalogcisa
- criticalexploitedCVE-2026-85046: Google Chromium V8 Type Confusion Vulnerabilitycisa-kev
- unknownexploitedMultiples vulnérabilités dans Google Chrome (04 septembre 2026)cert-fr-avis
- highCVE-2026-85053: Improper resource exposure in CacheStorage in Google Chrome prior to 152.0.7977.82 allowed a r…nvd
- lowCVE-2026-85052: Out of bounds read in CrashReporting in Google Chrome prior to 152.0.7977.82 allowed a remote …nvd
- highCVE-2026-85051: Type confusion in Compositing in Google Chrome prior to 152.0.7977.82 allowed a remote attacke…nvd
- criticalCVE-2026-85050: Out of bounds write in WebGL in Google Chrome on on Android prior to 152.0.7977.82 allowed a r…nvd
More from HKCERT Security Bulletins
- unknownPalo Alto Products Multiple Vulnerabilities2026-09-10
- unknownMongoDB Multiple Vulnerabilities2026-09-10
- unknownGoogle Chrome Multiple Vulnerabilities2026-09-10
- unknownCitrix Products Multiple Vulnerabilities2026-09-10
- unknownMozilla Firefox Denial of Service Vulnerability2026-09-09