A newly published CVE says every version of Chromium has a sandbox escape bug, and attackers are already using it.
The flaw is tracked as CVE-2026-85046 and was added to the National Vulnerability Database on September 4, 2026. The listing describes it as an actively exploited sandbox escape that leads to remote code execution and says it touches all Chromium versions. Beyond that headline claim, the material available right now doesn't include further technical detail, such as an attack vector, a CVSS score, or which build carries the fix. The report picked up modest early attention on Hacker News, drawing 34 points and six comments.
Chromium is the open-source engine underneath Chrome, Edge, Brave, and a handful of other browsers, so a sandbox bypass that reportedly spans every version is a bigger deal than a single-vendor bug. Sandbox escapes are especially prized by attackers because they turn one malicious webpage into a way past the isolation browsers use as a last line of defense, rather than just a crash or a data leak inside the tab.
Browser makers have historically moved fast once an actively exploited sandbox bug is confirmed, often shipping emergency updates within days. The practical advice here is boring but real: check for a browser update and install it, and treat the current writeup, which is mostly a headline so far, with appropriate caution.