Register for the AI for Security Summit: Join Figma, Perplexity & Wiz

CVE-2026-84330
vulnerability analysis and mitigation

Overview

CVE-2026-84330 is a UI misrepresentation vulnerability in Google Chrome on Android that allows a remote attacker to spoof the browser address bar via a crafted HTML page exploiting FullScreen mode. It affects all versions of Google Chrome for Android prior to 152.0.7977.75. The vulnerability was reported internally by Google on 2026-05-27 and publicly disclosed on 2026-09-01 alongside a stable channel update. It carries a CVSS v3.1 base score of 5.4 (Medium) (Chrome Releases, Red Hat Advisory, GitHub Advisory).

Technical details

The vulnerability is classified under CWE-451 (User Interface Misrepresentation of Critical Information) and CWE-1021 (Improper Restriction of Rendered UI Layers or Frames), and is associated with attack patterns including clickjacking (CAPEC-103), tapjacking (CAPEC-506), and credential prompt impersonation (CAPEC-654). When a user on Android visits a malicious website and the page enters FullScreen mode, Chrome fails to properly render or maintain the address bar, allowing the attacker-controlled page to visually substitute or obscure the legitimate URL. Exploitation requires no privileges and no special configuration, but does require user interaction — specifically, a victim must visit and interact with the crafted HTML page. The Chromium issue tracker references bug ID 517091927 for this vulnerability (Chrome Releases, GitHub Advisory).

Impact

Successful exploitation enables a remote, unauthenticated attacker to spoof the browser address bar on Android devices, deceiving users into believing they are visiting a legitimate website when they are not. The primary risk is phishing — users may be tricked into submitting credentials, financial information, or other sensitive data to an attacker-controlled page. The confidentiality impact is rated Low (limited data exposure risk) and availability impact is also Low, with no integrity impact assessed (GitHub Advisory, Red Hat Advisory).

Exploitability

There is no public proof-of-concept exploit and no evidence of in-the-wild exploitation at the time of disclosure (Red Hat Advisory). The EPSS score is approximately 0.162%, indicating a low near-term probability of exploitation. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. Exploitation is not automatable and requires user interaction, limiting its scalability compared to fully remote, zero-click vulnerabilities (GitHub Advisory).

Exploitation steps

  1. Craft a malicious HTML page: The attacker creates a webpage that programmatically triggers the browser's Fullscreen API (e.g., via element.requestFullscreen()) upon user interaction such as a click or page load gesture.
  2. Lure the victim: The attacker distributes the malicious URL via phishing emails, SMS, social media, or malicious ads targeting Android Chrome users.
  3. Trigger FullScreen mode: When the victim visits the page and the FullScreen transition occurs, Chrome on Android fails to properly display or maintain the address bar, allowing the attacker's page to render a fake UI that mimics a legitimate site's appearance.
  4. Harvest credentials or sensitive data: The spoofed page presents a convincing login form or prompt. The victim, believing they are on a trusted site, submits credentials or other sensitive information that is captured by the attacker (Chrome Releases, GitHub Advisory).

Indicators of compromise

  • Network: HTTP/HTTPS requests from Android Chrome clients to unfamiliar domains that immediately invoke the Fullscreen API; outbound form submissions (POST requests) to attacker-controlled endpoints following a FullScreen event.
  • Logs: Browser history or proxy logs showing visits to suspicious domains with FullScreen API usage patterns; short session durations followed by credential submission events.
  • User Reports: Users reporting unexpected full-screen transitions on unfamiliar websites, or login prompts appearing without a visible or recognizable address bar on Android Chrome.

Mitigation and workarounds

Google has released a fix in Chrome version 152.0.7977.75 for Android (and 152.0.7977.75/.76 for Windows/Mac/Linux). Users should update Google Chrome on Android to version 152.0.7977.75 or later immediately. Organizations should enforce automatic Chrome updates on managed Android devices via MDM policies. As a behavioral workaround, users should be cautious when websites enter FullScreen mode and verify the address bar before entering any sensitive information (Chrome Releases, Red Hat Advisory).

Community reactions

The vulnerability was covered by several cybersecurity news outlets as part of broader reporting on the Chrome 152 stable channel update, which addressed 26 security fixes including two Critical-severity use-after-free flaws. Coverage from CyberSecurityNews, GBHackers, CyberPress, and Cryptika highlighted the overall patch batch, with CVE-2026-84330 noted as one of the Medium-severity issues. The CIS Security Advisory also flagged the update as addressing multiple vulnerabilities that could allow arbitrary code execution in more severe cases (CyberSecurityNews, Chrome Releases).

Additional resources

Linux Distribution fix status

Fix availability across major Linux distributions and their releases.

Debian

Fixed

bookworm

chromium: 152.0.7977.75-1~deb12u1

Fixed

sid

chromium: 152.0.7977.75-1

Fixed

trixie

chromium: 152.0.7977.75-1~deb13u1

Fixed

SourceThis report was generated using AI

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management