All Chromium Versions Vulnerable to Sandbox RCE Exploitation
A newly disclosed vulnerability, identified as CVE‑2026‑85046, has been catalogued by the National Vulnerability Database (NVD). The entry describes a remote code execution flaw that can be triggered by an unauthenticated attacker through a specially crafted request to the affected software. The NVD lists the vulnerability as having a CVSS v3.1 base score of 9.8, classifying it as critical and indicating that the flaw can lead to full system compromise if exploited.
The flaw appears in the widely deployed Apache Tomcat web‑server, specifically affecting versions 10.1.0 through 10.1.14. It stems from an oversight in the handling of HTTP headers that allows an attacker to inject malicious code into the server’s processing pipeline. A patch addressing the issue was released by the Apache Software Foundation on 2026‑07