Out of Bounds Read in CrashReporting for Google Chrome
CVE-2026-85052

3.1LOW

Key Information:

Vendor

Google

Status
Vendor
CVE Published:
3 September 2026

What is CVE-2026-85052?

A vulnerability in Google Chrome's CrashReporting feature permits out of bounds read operations that could enable a remote attacker to access memory outside the intended sandbox environment. By utilizing a specially crafted HTML page, an attacker with access to the renderer process can exploit this flaw, potentially compromising sensitive information stored in memory. Users are encouraged to update to the latest version to mitigate any risks associated with this vulnerability.

Affected Version(s)

Chrome 152.0.7977.82

References

CVSS V3.1

Score:
3.1
Severity:
LOW
Confidentiality:
Low
Integrity:
None
Availability:
Low
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.