ZeroHour

CVE-2026-84350

mass

Use-After-Free in Google Chrome TabStrip Enables Out-of-Sandbox Code Execution

CVSS 3.1
8.8 high
EPSS
<1%p13
Published
()
Modified
AI analysis

CVE-2026-84350 is a use-after-free (CWE-416) in the TabStrip component of Google Chrome, fixed in version 152.0.7977.75. A remote attacker can trigger the flaw by using social engineering to get a victim to perform specific UI interactions in the browser. Successful exploitation allows arbitrary code execution outside the browser sandbox, which increases the potential impact compared to typical renderer-sandboxed bugs. All users running Google Chrome versions prior to 152.0.7977.75 are affected. Exploitation status is quiet: no public proof-of-concept is known, the flaw is not in CISA's KEV catalog, EPSS estimates only a 0.2% chance of exploitation within 30 days, and Chromium rates the underlying severity as Low despite the CVSS 3.1 score of 8.8 (High).

What to do: Update Google Chrome to 152.0.7977.75 or later, which contains the TabStrip fix, and verify enterprise fleets have completed the auto-update cycle. Because exploitation relies on social engineering and UI interaction, remind users to be cautious with prompts urging unusual browser interactions. There is no known active exploitation or public exploit, so routine patching is sufficient.

Affected
google chromeAll versions prior to 152.0.7977.75
Estimated exposure
masshundreds of millions of browser installs (Chrome's global install base is in the billions; a shrinking, unquantified share remains on pre-152 builds) — Chrome runs on an estimated 3+ billion devices worldwide, so even the minority of installs that have not yet auto-updated to 152.0.7977.75 plausibly exceeds one million systems, though the exact vulnerable population is unknown.

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Use after free in TabStrip in Google Chrome prior to 152.0.7977.75 allowed a remote attacker leveraging social engineering to execute arbitrary code outside the sandbox via UI Interaction. (Chromium security severity: Low)

Vendors
google
Products
chrome
Weakness
CWE-416
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.