AI analysis
CVE-2026-84353 is a use-after-free memory-corruption flaw (CWE-416) in the Shared Tab Groups feature of Google Chrome on Android. A remote attacker can trigger it by luring a user to a crafted HTML page, relying on social engineering to get the interaction required. Successful exploitation allows arbitrary code execution outside the browser sandbox, meaning the attacker can escape Chrome's process isolation and run code with broader system privileges. Only Chrome for Android versions prior to 152.0.7977.75 are affected; desktop Chrome users are not affected by this flaw. As of now there is no known in-the-wild exploitation, no public proof-of-concept, it is not in CISA's KEV catalog, and EPSS estimates only a 0.3% chance of exploitation in the next 30 days.
What to do: Update Chrome on Android to 152.0.7977.75 or later via the Google Play Store (Settings > About Chrome > check for updates) and let managed devices pull the patched build. Because exploitation requires user interaction and social engineering, also caution users against opening links or web pages from untrusted sources until they are patched. Enterprise admins should verify Android fleets have received the updated Chrome build through their EMM/MDM update policies.
Affected
| Google Chrome for Android | prior to 152.0.7977.75 |
Estimated exposure
masshundreds of millions to billions of Chrome-for-Android users (Chrome is the dominant mobile browser) — Chrome is the default or dominant browser on billions of Android devices worldwide, and although the flaw is limited to the Android Shared Tab Groups code and only unpatched versions prior to 152.0.7977.75 are exposed, the plausible…
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.