ZeroHour

CVE-2026-84353

mass

Use-After-Free RCE in Google Chrome for Android Shared Tab Groups

CVSS 3.1
9.6 critical
EPSS
<1%p24
Published
()
Modified
AI analysis

CVE-2026-84353 is a use-after-free memory-corruption flaw (CWE-416) in the Shared Tab Groups feature of Google Chrome on Android. A remote attacker can trigger it by luring a user to a crafted HTML page, relying on social engineering to get the interaction required. Successful exploitation allows arbitrary code execution outside the browser sandbox, meaning the attacker can escape Chrome's process isolation and run code with broader system privileges. Only Chrome for Android versions prior to 152.0.7977.75 are affected; desktop Chrome users are not affected by this flaw. As of now there is no known in-the-wild exploitation, no public proof-of-concept, it is not in CISA's KEV catalog, and EPSS estimates only a 0.3% chance of exploitation in the next 30 days.

What to do: Update Chrome on Android to 152.0.7977.75 or later via the Google Play Store (Settings > About Chrome > check for updates) and let managed devices pull the patched build. Because exploitation requires user interaction and social engineering, also caution users against opening links or web pages from untrusted sources until they are patched. Enterprise admins should verify Android fleets have received the updated Chrome build through their EMM/MDM update policies.

Affected
Google Chrome for Androidprior to 152.0.7977.75
Estimated exposure
masshundreds of millions to billions of Chrome-for-Android users (Chrome is the dominant mobile browser) — Chrome is the default or dominant browser on billions of Android devices worldwide, and although the flaw is limited to the Android Shared Tab Groups code and only unpatched versions prior to 152.0.7977.75 are exposed, the plausible…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Use after free in Shared Tab Groups in Google Chrome on on Android prior to 152.0.7977.75 allowed a remote attacker leveraging social engineering to execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Critical)

Vendors
google
Products
chrome
Weakness
CWE-416
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H

In the news

Two critical Chrome flaws put users at risk on malicious websites

Google patched 26 Chrome flaws, including two critical use-after-frees and an actively exploited V8 sandbox escape (CVE-2026-85046); update to 152.0.7977.82/.83.

Chrome's desktop update fixes 26 security issues, including critical use-after-free flaws CVE-2026-84353 in Shared Tab Groups and CVE-2026-84352 in WebGL, both allowing code execution outside the browser sandbox via crafted HTML pages. Google subsequently patched CVE-2026-85046, a high-severity V8 JavaScript engine flaw with exploits already in the wild that enables arbitrary code execution inside the Chrome sandbox; HKCERT rates the overall risk as extremely high. Fixed versions are 152.0.7977.82/.83 on Windows and Mac and 152.0.7977.82 on Linux.