CVE-2026-84335
massChrome TabStrip Authorization Flaw Enables Sandbox Escape via Compromised Renderer
CVE-2026-84335 is an incorrect authorization flaw (CWE-863) in the TabStrip component of Google Chrome that fails to properly enforce privilege boundaries. To exploit it, a remote attacker must first compromise the Chrome renderer process through a crafted HTML page and then use social engineering to get the user to perform an action, after which the attacker can execute arbitrary code outside the browser sandbox. Successful exploitation breaks Chrome's key sandbox security boundary, giving the attacker code execution with broader access on the victim's system than a renderer-only compromise would allow. Anyone running an affected version of Google Chrome prior to 152.0.7977.75 on desktop or mobile is potentially affected. There is currently no known in-the-wild exploitation, no public proof of concept, and the flaw is rated Medium severity by Chromium, though the two-step exploitation chain makes practical attacks more difficult.
What to do: Update Google Chrome to 152.0.7977.75 or later as soon as it is available in your release channel, and confirm the patched version via chrome://settings/help or the equivalent enterprise update channel. Because exploitation requires a prior renderer compromise and user interaction, keep automatic updates enabled and treat browser-borne social engineering lures as an additional attack vector. No workaround is specified; organizations managing Chrome via enterprise policies should verify fleet versions and enforce the update.
| Google Chrome | All versions prior to 152.0.7977.75 |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Incorrect authorization in TabStrip in Google Chrome prior to 152.0.7977.75 allowed a remote attacker who had compromised the renderer process and leveraged social engineering to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Medium)
- Vendors
- Products
- chrome
- Weakness
- CWE-863
- Vector
- CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:H
In the news0 stories
No ingested article mentions this CVE yet.