AI analysis
CVE-2026-85052 is an out-of-bounds read (CWE-125) in the CrashReporting component of Google Chrome prior to 152.0.7977.82. It is triggered when an attacker who has already compromised the Chrome renderer process loads a crafted HTML page, causing the browser to read memory outside the intended bounds. The attacker gains the ability to read memory outside the browser sandbox; Chromium rates the issue High even though the published CVSS 3.1 score is 3.1 (Low), because impact is limited to confidentiality (disclosure of memory beyond the sandbox) and requires a prior renderer compromise. All Google Chrome users running versions before 152.0.7977.82 are affected. No public proof-of-concept, CISA KEV listing, or known exploitation of this specific flaw exists (EPSS 0.2%), although a separate Chrome zero-day, CVE-2026-85046, has been reported exploited in the wild.
What to do: Update Chrome to 152.0.7977.82 or later via chrome://settings/help and verify the update has rolled out across managed fleets using patch-management/MDM version reporting. Since exploitation requires a prior renderer compromise, also apply fixes for other actively exploited Chrome flaws (e.g., the in-the-wild CVE-2026-85046) and restart the browser after updating. Treat this flaw as a routine patch-cycle item unless new exploitation evidence emerges.
Affected
| Google Chrome | prior to 152.0.7977.82 |
Estimated exposure
massbillions of Chrome installations running pre-152.0.7977.82 builds (Chrome's global user base exceeds 3 billion) — Chrome is the world's dominant browser with an estimated 3+ billion users, and every installation on a build earlier than 152.0.7977.82 is affected until updated.
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.