
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-84330 is a UI misrepresentation vulnerability in Google Chrome on Android that allows a remote attacker to spoof the browser address bar via a crafted HTML page exploiting FullScreen mode. It affects all versions of Google Chrome for Android prior to 152.0.7977.75. The vulnerability was reported internally by Google on 2026-05-27 and publicly disclosed on 2026-09-01 alongside a stable channel update. It carries a CVSS v3.1 base score of 5.4 (Medium) (Chrome Releases, Red Hat Advisory, GitHub Advisory).
The vulnerability is classified under CWE-451 (User Interface Misrepresentation of Critical Information) and CWE-1021 (Improper Restriction of Rendered UI Layers or Frames), and is associated with attack patterns including clickjacking (CAPEC-103), tapjacking (CAPEC-506), and credential prompt impersonation (CAPEC-654). When a user on Android visits a malicious website and the page enters FullScreen mode, Chrome fails to properly render or maintain the address bar, allowing the attacker-controlled page to visually substitute or obscure the legitimate URL. Exploitation requires no privileges and no special configuration, but does require user interaction — specifically, a victim must visit and interact with the crafted HTML page. The Chromium issue tracker references bug ID 517091927 for this vulnerability (Chrome Releases, GitHub Advisory).
Successful exploitation enables a remote, unauthenticated attacker to spoof the browser address bar on Android devices, deceiving users into believing they are visiting a legitimate website when they are not. The primary risk is phishing — users may be tricked into submitting credentials, financial information, or other sensitive data to an attacker-controlled page. The confidentiality impact is rated Low (limited data exposure risk) and availability impact is also Low, with no integrity impact assessed (GitHub Advisory, Red Hat Advisory).
There is no public proof-of-concept exploit and no evidence of in-the-wild exploitation at the time of disclosure (Red Hat Advisory). The EPSS score is approximately 0.162%, indicating a low near-term probability of exploitation. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. Exploitation is not automatable and requires user interaction, limiting its scalability compared to fully remote, zero-click vulnerabilities (GitHub Advisory).
element.requestFullscreen()) upon user interaction such as a click or page load gesture.Google has released a fix in Chrome version 152.0.7977.75 for Android (and 152.0.7977.75/.76 for Windows/Mac/Linux). Users should update Google Chrome on Android to version 152.0.7977.75 or later immediately. Organizations should enforce automatic Chrome updates on managed Android devices via MDM policies. As a behavioral workaround, users should be cautious when websites enter FullScreen mode and verify the address bar before entering any sensitive information (Chrome Releases, Red Hat Advisory).
The vulnerability was covered by several cybersecurity news outlets as part of broader reporting on the Chrome 152 stable channel update, which addressed 26 security fixes including two Critical-severity use-after-free flaws. Coverage from CyberSecurityNews, GBHackers, CyberPress, and Cryptika highlighted the overall patch batch, with CVE-2026-84330 noted as one of the Medium-severity issues. The CIS Security Advisory also flagged the update as addressing multiple vulnerabilities that could allow arbitrary code execution in more severe cases (CyberSecurityNews, Chrome Releases).
Fix availability across major Linux distributions and their releases.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."