ZeroHour

CVE-2026-84335

mass

Chrome TabStrip Authorization Flaw Enables Sandbox Escape via Compromised Renderer

CVSS 3.1
8.3 high
EPSS
<1%p14
Published
()
Modified
AI analysis

CVE-2026-84335 is an incorrect authorization flaw (CWE-863) in the TabStrip component of Google Chrome that fails to properly enforce privilege boundaries. To exploit it, a remote attacker must first compromise the Chrome renderer process through a crafted HTML page and then use social engineering to get the user to perform an action, after which the attacker can execute arbitrary code outside the browser sandbox. Successful exploitation breaks Chrome's key sandbox security boundary, giving the attacker code execution with broader access on the victim's system than a renderer-only compromise would allow. Anyone running an affected version of Google Chrome prior to 152.0.7977.75 on desktop or mobile is potentially affected. There is currently no known in-the-wild exploitation, no public proof of concept, and the flaw is rated Medium severity by Chromium, though the two-step exploitation chain makes practical attacks more difficult.

What to do: Update Google Chrome to 152.0.7977.75 or later as soon as it is available in your release channel, and confirm the patched version via chrome://settings/help or the equivalent enterprise update channel. Because exploitation requires a prior renderer compromise and user interaction, keep automatic updates enabled and treat browser-borne social engineering lures as an additional attack vector. No workaround is specified; organizations managing Chrome via enterprise policies should verify fleet versions and enforce the update.

Affected
Google ChromeAll versions prior to 152.0.7977.75
Estimated exposure
massbillions of Chrome installations (Chrome is the world's dominant browser across desktop and Android) — Chrome holds roughly two-thirds of global browser market share with a multi-billion active user base, so effectively all Chrome users on versions before 152.0.7977.75 are exposed, although the required renderer compromise plus social…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Incorrect authorization in TabStrip in Google Chrome prior to 152.0.7977.75 allowed a remote attacker who had compromised the renderer process and leveraged social engineering to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Medium)

Vendors
google
Products
chrome
Weakness
CWE-863
Vector
CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.