HeadlinesBriefing favicon HeadlinesBriefing.com

Chromium Sandbox RCE Exploited in All Versions

Hacker News •
×

A critical sandbox escape vulnerability, tracked as CVE-2026-85046, is being actively exploited in all Chromium versions, according to a NIST advisory. The flaw allows remote code execution, posing a severe risk to users of Chrome, Edge, and other Chromium-based browsers.

NIST's National Vulnerability Database details the issue, which has a high severity rating. Exploitation occurs in the wild, meaning attackers are already leveraging this vulnerability to compromise systems. Users are urged to apply patches immediately as browser vendors release updates.

The vulnerability impacts the sandboxing mechanism, which is designed to isolate web content from the underlying operating system. A successful exploit could allow an attacker to escape the sandbox and execute arbitrary code with the user's privileges.

Given the active exploitation, this is a zero-day threat. Security experts recommend enabling automatic updates and checking for browser patches regularly. The advisory provides technical details for mitigation, and organizations should prioritize updating all Chromium-based browsers to the latest versions to prevent potential breaches.