CVE-2026-84350
massUse-After-Free in Google Chrome TabStrip Enables Out-of-Sandbox Code Execution
CVE-2026-84350 is a use-after-free (CWE-416) in the TabStrip component of Google Chrome, fixed in version 152.0.7977.75. A remote attacker can trigger the flaw by using social engineering to get a victim to perform specific UI interactions in the browser. Successful exploitation allows arbitrary code execution outside the browser sandbox, which increases the potential impact compared to typical renderer-sandboxed bugs. All users running Google Chrome versions prior to 152.0.7977.75 are affected. Exploitation status is quiet: no public proof-of-concept is known, the flaw is not in CISA's KEV catalog, EPSS estimates only a 0.2% chance of exploitation within 30 days, and Chromium rates the underlying severity as Low despite the CVSS 3.1 score of 8.8 (High).
What to do: Update Google Chrome to 152.0.7977.75 or later, which contains the TabStrip fix, and verify enterprise fleets have completed the auto-update cycle. Because exploitation relies on social engineering and UI interaction, remind users to be cautious with prompts urging unusual browser interactions. There is no known active exploitation or public exploit, so routine patching is sufficient.
| google chrome | All versions prior to 152.0.7977.75 |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Use after free in TabStrip in Google Chrome prior to 152.0.7977.75 allowed a remote attacker leveraging social engineering to execute arbitrary code outside the sandbox via UI Interaction. (Chromium security severity: Low)
- Vendors
- Products
- chrome
- Weakness
- CWE-416
- Vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
In the news0 stories
No ingested article mentions this CVE yet.