[UPDATE] [hoch] Google Chrome / Microsoft Edge: Mehrere Schwachstellen
Actively exploited. At least one CVE in this advisory is listed in the CISA Known Exploited Vulnerabilities catalog — exploitation has been observed in the wild. Treat remediation as urgent.
Ein entfernter, anonymer Angreifer kann mehrere Schwachstellen in Google Chrome / Microsoft Edge ausnutzen, um beliebigen Programmcode auszuführen, um Informationen offenzulegen und um Sicherheitsmechanismen zu umgehen.
CSIRTS triage
- What
- Multiple vulnerabilities in Chrome allow remote code execution, information disclosure, and security mechanism bypass.
- Who is affected
- All Chrome browser users, particularly those visiting untrusted websites or receiving socially engineered content.
- Urgency
- Critical priority because remote code execution in a web browser is widely exploitable and frequently targeted; high-severity browser compromise affects all web-accessible user data and system access.
- Action
- Update Chrome to the latest version immediately; enable automatic updates if not already enabled.
AI-assisted analysis generated from the source advisory — verify against the original.
⚡ Watch Chrome
Get an email when a new Chrome advisory drops — max one per day, one-click unsubscribe.
Details
Original advisory: https://wid.cert-bund.de/portal/wid/securityadvisory?name=WID-SEC-2026-3175
Exploitation outlook
EPSS (FIRST.org) estimates each CVE’s probability of exploitation in the next 30 days — here is the CSIRTS.com read on those numbers.
- Low exploitation riskCVE-2026-850420.34% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 27% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-850430.32% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 25% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-850440.26% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 18% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-850450.24% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 15% of all EPSS-scored CVEs.
- Exploitation confirmedCVE-2026-85046Already exploited in the wild (CISA KEV) — the prediction phase is over. Patch now. Riskier than 65% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-850470.34% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 27% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-850480.33% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 25% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-850490.31% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 23% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-850500.34% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 27% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-850510.34% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 27% of all EPSS-scored CVEs.
Referenced CVEs
| CVE | CSIRTS overview | External |
|---|---|---|
| CVE-2026-85042 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-85043 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-85044 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-85045 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-85046 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-85047 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-85048 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-85049 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-85050 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-85051 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-85052 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-85053 | coverage & exploitation status | NVD · CVE.org |
Same CVEs, other sources
How other CERTs, PSIRTs and databases cover the vulnerabilities in this advisory.
- unknownexploitedCVE-2026-85046: Chromium: CVE-2026-85046 Type confusion in V8msrc
- unknownexploitedDSA-6484-1 chromium - security updatedebian
- unknownexploitedGoogle security advisory (AV26-883) – Update 1cccs
- unknownexploitedNCSC-2026-0341 [1.00] [M/H] Kwetsbaarheden verholpen in Google Chromencsc-nl
- highexploitedCISA Adds One Known Exploited Vulnerability to Catalogcisa
- unknownexploitedGoogle Chrome Multiple Vulnerabilitieshkcert
- unknownexploitedMultiples vulnérabilités dans Google Chrome (04 septembre 2026)cert-fr-avis
- criticalexploitedCVE-2026-85046: Google Chromium V8 Type Confusion Vulnerabilitycisa-kev
- highCVE-2026-85053: Improper resource exposure in CacheStorage in Google Chrome prior to 152.0.7977.82 allowed a r…nvd
- lowCVE-2026-85052: Out of bounds read in CrashReporting in Google Chrome prior to 152.0.7977.82 allowed a remote …nvd
- highCVE-2026-85051: Type confusion in Compositing in Google Chrome prior to 152.0.7977.82 allowed a remote attacke…nvd
- criticalCVE-2026-85050: Out of bounds write in WebGL in Google Chrome on on Android prior to 152.0.7977.82 allowed a r…nvd
Recent advisories for Google Chrome /
A cluster of recent advisories against the same product widens the attack surface — attackers routinely chain freshly published CVEs on one product, so review these together.
- unknownexploitedGoogle Chrome Multiple Vulnerabilitieshkcert · 2026-09-10
- unknownexploitedNCSC-2026-0354 [1.00] [M/H] Kwetsbaarheid verholpen in Google Chromencsc-nl · 2026-09-09
- high[NEU] [hoch] Google Chrome: Mehrere Schwachstellen ermöglichen nicht spezifizierten Angriffcert-bund · 2026-09-09
- high[UPDATE] [hoch] Google Chrome: Mehrere Schwachstellencert-bund · 2026-09-09
- mediumCVE-2026-87658: Information leak in Extensions in Google Chrome prior to 153.0.8010.36 allowed a remote attack…nvd · 2026-09-09
- lowCVE-2026-87657: Use after free in V8 in Google Chrome prior to 153.0.8010.36 allowed a remote attacker who had…nvd · 2026-09-09
More from CERT-Bund (BSI) Security Advisories
- medium[UPDATE] [mittel] OpenSSH: Mehrere Schwachstellen2026-09-10
- medium[UPDATE] [mittel] Linux Kernel: Mehrere Schwachstellen2026-09-10
- high[UPDATE] [hoch] OpenVPN: Mehrere Schwachstellen2026-09-10
- medium[UPDATE] [mittel] gzip: Mehrere Schwachstellen2026-09-10
- medium[UPDATE] [mittel] Linux Kernel: Mehrere Schwachstellen2026-09-10