A critical remote code execution vulnerability affecting all Chromium versions is currently being exploited in the wild. The flaw bypasses the browser's sandbox protection, allowing attackers to execute arbitrary code with full system access.
The vulnerability, tracked as CVE-2026-85046, has been documented in the National Vulnerability Database and is listed as actively exploited. The sandbox escape affects all versions of Chromium, the open-source project underlying Chrome, Edge, and numerous other browsers.
The active exploitation status indicates the vulnerability is being weaponized in real-world attacks. Users of Chromium-based browsers face immediate risk, as the sandbox is a critical security layer designed to isolate browser processes from the underlying system.
The vulnerability has garnered significant attention from the security community, with 104 comments on Hacker News discussing its implications. Affected users are advised to apply patches immediately once available. Browser vendors typically prioritize sandbox escapes due to their severity and the direct path to system compromise they provide to attackers.
Details are available on the National Vulnerability Database and have been discussed extensively in security forums.
Mullvad is discontinuing its public encrypted DNS servers and redirecting resources to sponsor Quad9, an alternative privacy-focused DNS provider. The move consolidates the privacy DNS landscape.
Identity verification company IDScan faces multiple lawsuits after hackers allegedly accessed and attempted to sell driver's license data for over 153 million individuals.
Attackers are actively exploiting a critical authentication bypass vulnerability in Citrix NetScaler, according to Previdian. CVE-2026-19490 allows threat actors to circumvent security controls on the widely-deployed application delivery platform.