
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-85052 is an out-of-bounds read vulnerability in the CrashReporting component of Google Chrome that allows a remote attacker who has already compromised the renderer process to read memory outside the sandbox via a crafted HTML page. It affects all versions of Google Chrome prior to 152.0.7977.82. The vulnerability was reported by Google internally on 2026-04-13 and publicly disclosed on September 3, 2026, when Chrome 152.0.7977.82 was released. It carries a CVSS v3.1 base score of 3.1 (Low), reflecting the high attack complexity and limited confidentiality impact (Chrome Releases, GitHub Advisory).
The vulnerability is classified as CWE-125 (Out-of-bounds Read) and resides in Chrome's CrashReporting subsystem. Exploitation requires an attacker to have already compromised the Chrome renderer process — a significant precondition — after which a crafted HTML page can trigger the out-of-bounds read, allowing memory outside the sandbox boundary to be accessed. The attack vector is network-based, requires user interaction (visiting a malicious page), and has high attack complexity due to the prerequisite renderer compromise. The Chromium issue tracker references bug ID 502304489 (Chrome Releases, GitHub Advisory).
Successful exploitation results in a limited memory disclosure — an attacker who has already broken out of the renderer can read arbitrary memory outside the Chrome sandbox, potentially exposing sensitive data held in process memory such as credentials, session tokens, or other in-memory secrets. There is no integrity or availability impact. The scope of impact is constrained to the local Chrome process memory and does not directly enable code execution or lateral movement on its own (GitHub Advisory, Feedly).
There is no public proof-of-concept exploit for CVE-2026-85052, and no evidence of in-the-wild exploitation has been observed. The EPSS score is approximately 0.20%, indicating a low near-term exploitation probability. The NVD SSVC assessment classifies exploitation as "none" and automation as "no." Notably, the same Chrome 152.0.7977.82 release bundle includes CVE-2026-85046 (V8 type confusion), for which Google confirmed active in-the-wild exploitation — CVE-2026-85052 itself is not listed as exploited (Chrome Releases, GitHub Advisory).
Google has released a patch in Chrome 152.0.7977.82/.83 for Windows and Mac, and 152.0.7977.82 for Linux. Users and administrators should update Chrome to version 152.0.7977.82 or later immediately. No configuration-based workaround is available; upgrading is the only remediation. Enterprise administrators can enforce the update via policy management tools. Microsoft Edge (Chromium-based) users should also monitor the Microsoft Security Response Center for a corresponding Edge update (Chrome Releases, Microsoft).
The September 3, 2026 Chrome stable update received broad coverage primarily due to the co-patched CVE-2026-85046 (V8 type confusion), which was confirmed exploited in the wild. Coverage from outlets such as HotHardware and IT-Connect framed the release as an urgent zero-day patch, though CVE-2026-85052 itself was not the focus. CIS issued an advisory noting multiple vulnerabilities in the update could allow arbitrary code execution. The security community's attention was largely directed at CVE-2026-85046 rather than CVE-2026-85052 specifically (Chrome Releases, CIS Advisory).
Fix availability across major Linux distributions and their releases.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."