CVE-2026-85052: Out of bounds read in CrashReporting
Out of bounds read in CrashReporting in Google Chrome prior to 152.0.7977.82 allowed a remote attacker who had compromised the renderer process to read memory outside the sandbox via a crafted HTML page. (Chromium security severity: High)
Credit
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 152.0.7977.82
Event History
Peer vulnerabilities
Found alongside the following vulnerabilities.
Frequently Asked Questions
What level of access does an attacker need before this issue can be exploited?
The attacker must first compromise the Chrome renderer process. They can then use a crafted HTML page to trigger the out-of-bounds read and read memory outside the sandbox.
Which Chrome versions need to be updated?
Google Chrome versions prior to 152.0.7977.82 are affected. Update Chrome to 152.0.7977.82 or later.
What is the potential impact after exploitation?
A successful exploit allows memory to be read outside the renderer sandbox. The issue is rated High by Chromium.