Chromium: Active RCE Sandbox Escape Exploited in the Wild

Original: Actively exploited sandbox RCE in all Chromium versions

Why This Matters

A sandbox RCE in all Chromium versions puts billions of users across major browsers at immediate risk.

A critical remote code execution vulnerability enabling sandbox escape has been identified in all Chromium versions and is actively exploited. The flaw is tracked as CVE-2026-85046 and listed in the NIST National Vulnerability Database.

The NIST National Vulnerability Database (NVD) has published an entry for CVE-2026-85046, a sandbox escape remote code execution (RCE) vulnerability affecting all versions of Chromium. The vulnerability is noted as actively exploited in the wild, meaning threat actors are already leveraging it against real targets. Chromium serves as the open-source foundation for Google Chrome, Microsoft Edge, Brave, Opera, and numerous other browsers, making the scope of affected users extremely broad. At the time of reporting, full technical details, CVSS score, and patch availability were limited based on the source page content. Users and organizations relying on Chromium-based browsers are advised to monitor official vendor security advisories for patches and mitigations. Sandbox escape vulnerabilities are considered severe because they allow attackers to break out of the browser's security isolation layer and execute arbitrary code on the underlying host system.

Source

nvd.nist.gov — Read original →