Google Chrome < 152.0.7977.82 Multiple Vulnerabilities

critical Nessus Plugin ID 342683

Synopsis

A web browser installed on the remote macOS host is affected by multiple vulnerabilities.

Description

The version of Google Chrome installed on the remote macOS host is prior to 152.0.7977.82. It is, therefore, affected by multiple vulnerabilities as referenced in the 2026_09_stable-channel-update-for-desktop_01882797386 advisory.

- Use after free in Skia. (CVE-2026-85049)

- Improper input validation in Transactions Platform in Google Chrome on on iOS prior to 152.0.7977.82 allowed a remote attacker to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Medium) (CVE-2026-85047)

- Out of bounds read in CrashReporting in Google Chrome prior to 152.0.7977.82 allowed a remote attacker who had compromised the renderer process to read memory outside the sandbox via a crafted HTML page. (Chromium security severity: High) (CVE-2026-85052)

- Type confusion in V8. (CVE-2026-85046)

- Incomplete cleanup in Network. (CVE-2026-85043)

Note that Nessus has not tested for these issues but has instead relied only on the application's self-reported version number.

Solution

Upgrade to Google Chrome version 152.0.7977.82 or later.

See Also

https://crbug.com/502304489

https://crbug.com/513790581

https://crbug.com/517482830

https://crbug.com/533502257

https://crbug.com/540357382

https://crbug.com/542403045

https://crbug.com/547819997

https://crbug.com/549350408

https://crbug.com/552689418

https://crbug.com/553119925

https://crbug.com/553345874

https://crbug.com/553449113

http://www.nessus.org/u?d807043a

Plugin Details

Severity: Critical

ID: 342683

File Name: macosx_google_chrome_152_0_7977_82.nasl

Version: 1.3

Type: Local

Agent: macosx

Published: 9/3/2026

Updated: 9/4/2026

Supported Sensors: Frictionless Assessment AWS, Frictionless Assessment Azure, Frictionless Assessment Agent, Nessus Agent, Tenable Cloud Security, Tenable Self-Hosted Container Security, Nessus

Risk Information

VPR

Risk Factor: Critical

Score: 9.4

Percentile: 99.82

CVSS v2

Risk Factor: Critical

Base Score: 10

Temporal Score: 8.3

Vector: CVSS2#AV:N/AC:L/Au:N/C:C/I:C/A:C

CVSS Score Source: CVE-2026-85049

CVSS v3

Risk Factor: Critical

Base Score: 9.6

Temporal Score: 8.9

Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H

Temporal Vector: CVSS:3.0/E:F/RL:O/RC:C

CVSS Score Source: CVE-2026-85050

Vulnerability Information

CPE: cpe:/a:google:chrome

Required KB Items: installed_sw/Google Chrome

Exploit Available: true

Exploit Ease: Exploits are available

Patch Publication Date: 9/3/2026

Vulnerability Publication Date: 9/3/2026

CISA Known Exploited Vulnerability Due Dates: 9/18/2026

Reference Information

CVE: CVE-2026-85042, CVE-2026-85043, CVE-2026-85044, CVE-2026-85045, CVE-2026-85046, CVE-2026-85047, CVE-2026-85048, CVE-2026-85049, CVE-2026-85050, CVE-2026-85051, CVE-2026-85052, CVE-2026-85053