CVE-2026-84325
massImproper Input Validation in Chrome DataTransfer Allows Access-Restriction Bypass
CVE-2026-84325 is an improper input validation flaw (CWE-20) in the DataTransfer component of Google Chrome, rated High by Chromium and assigned a CVSS 3.1 base score of 9.8. A remote attacker must combine the flaw with social engineering, persuading a user into a data-transfer interaction that, together with an application co-installed on the same system, bypasses system access restrictions. Successful exploitation grants a bypass of restrictions normally enforced between the browser and locally installed software, with the practical impact depending on the privileges of the co-installed app involved. All users of Google Chrome prior to 152.0.7977.75 are affected; note that the description indicates user interaction (social engineering) is required, despite the UI:N value in the vendor-assigned CVSS vector. There is no public proof-of-concept, the flaw is not in the CISA KEV catalog, and EPSS assigns only a 0.2% probability of exploitation within 30 days, so no exploitation is currently known.
What to do: Update Google Chrome to 152.0.7977.75 or later on all endpoints, verifying versions via chrome://settings/help or your fleet-management reporting. Since exploitation requires social engineering plus a co-installed app, inventory locally installed applications that interact with browser data transfers and remind users to treat drag-and-drop/data-transfer prompts with caution. With no public PoC or in-the-wild exploitation known, patching within your normal update cadence is reasonable, though prioritize for high-risk or privileged users.
| google chrome | prior to 152.0.7977.75 |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Improper input validation in DataTransfer in Google Chrome prior to 152.0.7977.75 allowed a remote attacker leveraging social engineering to bypass system access restrictions via a co-installed app. (Chromium security severity: High)
- Vendors
- Products
- chrome
- Weakness
- CWE-20
- Vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
In the news0 stories
No ingested article mentions this CVE yet.