Impact
An out‑of‑bounds read in the CrashReporting component of Google Chrome allows a remote attacker, who has already compromised the renderer process, to read memory outside the intended sandbox limits. The vulnerability is triggered by a crafted HTML page served to the victim’s browser. The information read could include sensitive data such as passwords, tokens or other secrets stored in renderer memory, enabling attackers to exfiltrate confidential data but not necessarily granting arbitrary code execution.
Affected Systems
Google Chrome versions prior to 152.0.7977.82 on any supported platform are vulnerable. All users running the stable channel of Chrome were exposed until the update issued on 2026‑09‑18.
Risk and Exploitability
Chromium lists this issue with a CVSS score of 3.1, indicating a low severity. The EPSS score is not available and the vulnerability is not listed in CISA KEV. The likely attack vector is a malicious web page delivered to the victim’s browser; the attacker must first compromise the renderer process, which could result from other vulnerabilities. Because the memory exposure is limited to renderer memory, the potential impact is low, though it may expose sensitive data stored in that process. Prompt patching is recommended to eliminate this vector.
OpenCVE Enrichment
Debian DLA
Debian DSA