Description
Out of bounds read in CrashReporting in Google Chrome prior to 152.0.7977.82 allowed a remote attacker who had compromised the renderer process to read memory outside the sandbox via a crafted HTML page. (Chromium security severity: High)
Published: 2026-09-03
Score: 3.1 Low
EPSS: < 1% Very Low
KEV: No
Impact: Remote memory disclosure via renderer sandbox bypass
Action: Immediate Patch
AI Analysis

Impact

An out‑of‑bounds read in the CrashReporting component of Google Chrome allows a remote attacker, who has already compromised the renderer process, to read memory outside the intended sandbox limits. The vulnerability is triggered by a crafted HTML page served to the victim’s browser. The information read could include sensitive data such as passwords, tokens or other secrets stored in renderer memory, enabling attackers to exfiltrate confidential data but not necessarily granting arbitrary code execution.

Affected Systems

Google Chrome versions prior to 152.0.7977.82 on any supported platform are vulnerable. All users running the stable channel of Chrome were exposed until the update issued on 2026‑09‑18.

Risk and Exploitability

Chromium lists this issue with a CVSS score of 3.1, indicating a low severity. The EPSS score is not available and the vulnerability is not listed in CISA KEV. The likely attack vector is a malicious web page delivered to the victim’s browser; the attacker must first compromise the renderer process, which could result from other vulnerabilities. Because the memory exposure is limited to renderer memory, the potential impact is low, though it may expose sensitive data stored in that process. Prompt patching is recommended to eliminate this vector.

Generated by OpenCVE AI on September 3, 2026 at 23:32 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Install the Chrome update released on 2026‑09‑18 or any later version, which removes the bug in CrashReporting.
  • Ensure that Chrome’s default sandbox and site isolation features are enabled; avoid disabling flags that protect the renderer process from elevated privileges.
  • Maintain up‑to‑date operating‑system and antivirus/endpoint protection software, and monitor for anomalous memory access or data exfiltration attempts.

Generated by OpenCVE AI on September 3, 2026 at 23:32 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Debian DLA Debian DLA DLA-4776-1 chromium security update
Debian DSA Debian DSA DSA-6484-1 chromium security update
History

Tue, 08 Sep 2026 16:30:00 +0000

Type Values Removed Values Added
CPEs cpe:2.3:a:google:chrome:*:*:*:*:*:*:*:*

Fri, 04 Sep 2026 00:00:00 +0000

Type Values Removed Values Added
Title Out-of-Bounds Read in CrashReporting Allows Memory Disclosure Beyond Renderer Sandbox

Thu, 03 Sep 2026 21:30:00 +0000

Type Values Removed Values Added
Title Out-of-Bounds Read in CrashReporting Allows Memory Disclosure Beyond Renderer Sandbox
Metrics cvssV3_1

{'score': 3.1, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:L/I:N/A:N'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 03 Sep 2026 20:45:00 +0000

Type Values Removed Values Added
First Time appeared Google
Google chrome
Vendors & Products Google
Google chrome

Thu, 03 Sep 2026 19:30:00 +0000

Type Values Removed Values Added
Description Out of bounds read in CrashReporting in Google Chrome prior to 152.0.7977.82 allowed a remote attacker who had compromised the renderer process to read memory outside the sandbox via a crafted HTML page. (Chromium security severity: High)
Weaknesses CWE-125
References

cve-icon MITRE

Status: PUBLISHED

Assigner: Chrome

Published:

Updated: 2026-09-03T20:06:20.468Z

Reserved: 2026-09-02T21:13:20.704Z

Link: CVE-2026-85052

cve-icon Vulnrichment

Updated: 2026-09-03T20:06:14.333Z

cve-icon NVD

Status : Analyzed

Published: 2026-09-03T20:17:26.857

Modified: 2026-09-08T16:17:47.257

Link: CVE-2026-85052

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-03T23:45:04Z

Weaknesses