Junglewise Threat Intelligence

CVE-2026-85052: Google Chrome out of bounds read in CrashReporting

CVE-2026-85052 · Severity: low · CVSS 3.1 · Published 2026-09-03

Technologies: Google Chrome. Vendors: Google.

Executive brief

Google Chrome's crash reporting component contains an out-of-bounds memory read vulnerability. An attacker who has already compromised Chrome's rendering process could exploit this flaw via a crafted webpage to read sensitive data from outside the sandbox security boundary, potentially exposing confidential information or aiding further attacks.

Technical details

This is an out-of-bounds read vulnerability in the CrashReporting component of Google Chrome. The flaw requires an attacker to have already compromised the renderer process, and can be triggered via a specially crafted HTML page. By reading memory outside the sandbox boundary, an attacker can bypass Chrome's security isolation and potentially leak sensitive data. The vulnerability affects Chrome versions prior to 152.0.7977.82, and a fix is available in that release version.

Affected products

  • Google Chrome prior to 152.0.7977.82

Timeline

  • 2026-09-03: disclosed
  • 2026-09-03: patched

References

Related threats