Register for the AI for Security Summit: Join Figma, Perplexity & Wiz

CVE-2026-85052
vulnerability analysis and mitigation

Overview

CVE-2026-85052 is an out-of-bounds read vulnerability in the CrashReporting component of Google Chrome that allows a remote attacker who has already compromised the renderer process to read memory outside the sandbox via a crafted HTML page. It affects all versions of Google Chrome prior to 152.0.7977.82. The vulnerability was reported by Google internally on 2026-04-13 and publicly disclosed on September 3, 2026, when Chrome 152.0.7977.82 was released. It carries a CVSS v3.1 base score of 3.1 (Low), reflecting the high attack complexity and limited confidentiality impact (Chrome Releases, GitHub Advisory).

Technical details

The vulnerability is classified as CWE-125 (Out-of-bounds Read) and resides in Chrome's CrashReporting subsystem. Exploitation requires an attacker to have already compromised the Chrome renderer process — a significant precondition — after which a crafted HTML page can trigger the out-of-bounds read, allowing memory outside the sandbox boundary to be accessed. The attack vector is network-based, requires user interaction (visiting a malicious page), and has high attack complexity due to the prerequisite renderer compromise. The Chromium issue tracker references bug ID 502304489 (Chrome Releases, GitHub Advisory).

Impact

Successful exploitation results in a limited memory disclosure — an attacker who has already broken out of the renderer can read arbitrary memory outside the Chrome sandbox, potentially exposing sensitive data held in process memory such as credentials, session tokens, or other in-memory secrets. There is no integrity or availability impact. The scope of impact is constrained to the local Chrome process memory and does not directly enable code execution or lateral movement on its own (GitHub Advisory, Feedly).

Exploitability

There is no public proof-of-concept exploit for CVE-2026-85052, and no evidence of in-the-wild exploitation has been observed. The EPSS score is approximately 0.20%, indicating a low near-term exploitation probability. The NVD SSVC assessment classifies exploitation as "none" and automation as "no." Notably, the same Chrome 152.0.7977.82 release bundle includes CVE-2026-85046 (V8 type confusion), for which Google confirmed active in-the-wild exploitation — CVE-2026-85052 itself is not listed as exploited (Chrome Releases, GitHub Advisory).

Mitigation and workarounds

Google has released a patch in Chrome 152.0.7977.82/.83 for Windows and Mac, and 152.0.7977.82 for Linux. Users and administrators should update Chrome to version 152.0.7977.82 or later immediately. No configuration-based workaround is available; upgrading is the only remediation. Enterprise administrators can enforce the update via policy management tools. Microsoft Edge (Chromium-based) users should also monitor the Microsoft Security Response Center for a corresponding Edge update (Chrome Releases, Microsoft).

Community reactions

The September 3, 2026 Chrome stable update received broad coverage primarily due to the co-patched CVE-2026-85046 (V8 type confusion), which was confirmed exploited in the wild. Coverage from outlets such as HotHardware and IT-Connect framed the release as an urgent zero-day patch, though CVE-2026-85052 itself was not the focus. CIS issued an advisory noting multiple vulnerabilities in the update could allow arbitrary code execution. The security community's attention was largely directed at CVE-2026-85046 rather than CVE-2026-85052 specifically (Chrome Releases, CIS Advisory).

Additional resources

Linux Distribution fix status

Fix availability across major Linux distributions and their releases.

Debian

Fixed

bookworm

chromium: 152.0.7977.82-1~deb12u1

Fixed

sid

chromium: 152.0.7977.82-1

Fixed

trixie

chromium: 152.0.7977.82-1~deb13u1

Fixed

SourceThis report was generated using AI

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management