
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-84355 is an incorrect authorization vulnerability in the Navigation component of Google Chrome that allows a remote attacker who has already compromised the renderer process to bypass the web origin policy via a crafted HTML page. It affects all versions of Google Chrome prior to 152.0.7977.75. The vulnerability was reported to Google on 2026-05-10 and patched in the stable channel update released on 2026-09-01. It carries a CVSS v3.1 base score of 3.1 (Low) and is rated Medium severity by Chromium's internal security scale (Red Hat CVE, Chrome Releases).
The root cause is classified under CWE-346 (Origin Validation Error) and CWE-863 (Incorrect Authorization), meaning Chrome's Navigation component fails to properly enforce web origin policy checks under certain conditions. Exploitation requires that an attacker has already compromised the renderer process — a significant precondition — and then uses a specially crafted HTML page to trigger the authorization bypass. The attack vector is network-based, requires user interaction, and has high attack complexity, limiting its practical exploitability. The Chromium issue tracker references bug ID 511774376 for this vulnerability (Chrome Releases, Red Hat CVE).
Successful exploitation results in a limited confidentiality impact — specifically, a low-severity information disclosure — with no integrity or availability impact. Because the attacker must already have renderer process compromise as a precondition, this vulnerability is most relevant as a sandbox escape or policy bypass step in a multi-stage attack chain rather than a standalone exploit. The scope is unchanged, meaning the impact is confined to the browser's security context without privilege escalation beyond the renderer sandbox boundary (Red Hat CVE).
There is no public proof-of-concept exploit and no evidence of in-the-wild exploitation at the time of disclosure. The EPSS score is approximately 0.00175 (0.175%), reflecting a very low probability of exploitation in the near term. The vulnerability is not listed in CISA's Known Exploited Vulnerabilities (KEV) catalog. The high attack complexity and the requirement for prior renderer compromise significantly reduce the likelihood of opportunistic exploitation (Red Hat CVE, Chrome Releases).
Google has released a fix in Chrome stable channel version 152.0.7977.75 (Linux) and 152.0.7977.75/.76 (Windows and Mac). Users and administrators should update Chrome to version 152.0.7977.75 or later immediately. Enterprise administrators should use deployment tools (e.g., Google Admin Console, SCCM, or Intune) to push the update across managed endpoints. No configuration-based workaround is available; patching is the only remediation (Chrome Releases, Microsoft MSRC).
The vulnerability was part of a broader Chrome stable channel update addressing 26 security fixes, including two Critical-rated use-after-free flaws, which drew more significant media attention than CVE-2026-84355 itself. Security news outlets including CyberSecurityNews, GBHackers, and CyberPress covered the overall Chrome update, noting the critical flaws as the headline items. CVE-2026-84355, rated Medium, received minimal individual commentary given its low CVSS score and high exploitation preconditions (CyberSecurityNews, GBHackers, CyberPress).
Fix availability across major Linux distributions and their releases.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."