ZeroHour

CVE-2026-85052

mass

Out-of-bounds read in Google Chrome CrashReporting leaks memory beyond sandbox

CVSS 3.1
3.1 low
EPSS
<1%p8
Published
()
Modified
AI analysis

CVE-2026-85052 is an out-of-bounds read (CWE-125) in the CrashReporting component of Google Chrome prior to 152.0.7977.82. It is triggered when an attacker who has already compromised the Chrome renderer process loads a crafted HTML page, causing the browser to read memory outside the intended bounds. The attacker gains the ability to read memory outside the browser sandbox; Chromium rates the issue High even though the published CVSS 3.1 score is 3.1 (Low), because impact is limited to confidentiality (disclosure of memory beyond the sandbox) and requires a prior renderer compromise. All Google Chrome users running versions before 152.0.7977.82 are affected. No public proof-of-concept, CISA KEV listing, or known exploitation of this specific flaw exists (EPSS 0.2%), although a separate Chrome zero-day, CVE-2026-85046, has been reported exploited in the wild.

What to do: Update Chrome to 152.0.7977.82 or later via chrome://settings/help and verify the update has rolled out across managed fleets using patch-management/MDM version reporting. Since exploitation requires a prior renderer compromise, also apply fixes for other actively exploited Chrome flaws (e.g., the in-the-wild CVE-2026-85046) and restart the browser after updating. Treat this flaw as a routine patch-cycle item unless new exploitation evidence emerges.

Affected
Google Chromeprior to 152.0.7977.82
Estimated exposure
massbillions of Chrome installations running pre-152.0.7977.82 builds (Chrome's global user base exceeds 3 billion) — Chrome is the world's dominant browser with an estimated 3+ billion users, and every installation on a build earlier than 152.0.7977.82 is affected until updated.

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Out of bounds read in CrashReporting in Google Chrome prior to 152.0.7977.82 allowed a remote attacker who had compromised the renderer process to read memory outside the sandbox via a crafted HTML page. (Chromium security severity: High)

Vendors
google
Products
chrome
Weakness
CWE-125
Vector
CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:L/I:N/A:N

In the news

Google Chrome Zero-day Vulnerability Exploited in the Wild (CVE-2026-85046)

Google patched 12 Chrome flaws including in-the-wild V8 zero-day CVE-2026-85046; CISA added it to the KEV catalog.

Google released Chrome 152.0.7977.82/.83 for Windows and Mac (152.0.7977.82 for Linux) fixing 12 vulnerabilities, including CVE-2026-85046, a type confusion flaw in the V8 JavaScript engine being exploited in the wild. CISA added CVE-2026-85046 to its Known Exploited Vulnerabilities Catalog with a patch deadline of September 18, 2026. This is Chrome's sixth zero-day patched in 2026, following CVE-2026-2441, CVE-2026-3909, CVE-2026-3910, CVE-2026-5281 and CVE-2026-11645. The other 11 fixes include use-after-free, out-of-bounds, race condition and input validation flaws in Skia, WebGL, DevTools, Network, Compositing and other components.