
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-84356 is a UI misrepresentation vulnerability in the FullScreen feature of Google Chrome that allows a remote attacker to spoof the browser's address bar via a crafted HTML page. It affects all versions of Google Chrome prior to 152.0.7977.75. The vulnerability was reported by researcher Francesco Topol (k4tedu) on April 18, 2026, and publicly disclosed on September 1, 2026, when Google released Chrome 152.0.7977.75 (Chrome Releases). It carries a CVSS v3.1 base score of 4.3 (Medium) and is rated Low severity by Chromium's internal security classification (Red Hat CVE).
The vulnerability is classified under CWE-1021 (Improper Restriction of Rendered UI Layers or Frames) and CWE-451 (User Interface Misrepresentation of Critical Information), reflecting a flaw in how Chrome renders the browser UI during FullScreen mode (Red Hat CVE). When a user enters full-screen mode via a crafted HTML page, the browser fails to properly restrict or display the address bar, allowing an attacker-controlled page to present a fraudulent URL or UI element in place of the legitimate browser chrome. Exploitation requires user interaction — specifically, a victim must visit and interact with the attacker's crafted page — and no authentication or elevated privileges are required on the attacker's side. The attack vector is network-based, and the technical impact is limited to integrity (UI spoofing), with no confidentiality or availability impact (Red Hat CVE).
Successful exploitation allows an unauthenticated remote attacker to deceive users into believing they are visiting a legitimate website by spoofing the browser's address bar while in full-screen mode, potentially facilitating phishing attacks or credential harvesting. The impact is limited to integrity — there is no direct data exfiltration, code execution, or denial of service. However, the social engineering potential is significant, as users may enter sensitive information (e.g., passwords, payment details) into attacker-controlled pages that appear to be trusted sites (Red Hat CVE, Chrome Releases).
There is no public proof-of-concept exploit and no evidence of in-the-wild exploitation at this time (Red Hat CVE). The vulnerability is not listed in CISA's Known Exploited Vulnerabilities (KEV) catalog, and NVD's SSVC assessment confirms exploitation is currently "none" and the vulnerability is not automatable. The EPSS score is approximately 0.162%, indicating a low probability of exploitation in the near term. Exploitation requires user interaction, further reducing the practical risk.
element.requestFullscreen()) and renders a fake browser UI — including a spoofed address bar displaying a trusted domain (e.g., https://bank.com).Google has patched this vulnerability in Chrome version 152.0.7977.75 (Linux) and 152.0.7977.75/.76 (Windows and Mac); users should update immediately via Chrome's built-in update mechanism (Chrome Releases). Microsoft has also issued guidance for Edge users affected by the underlying Chromium vulnerability (Microsoft MSRC). As a precautionary measure, users should be advised to press Esc to exit full-screen mode when visiting unfamiliar sites and to verify the URL in the address bar before entering sensitive information. No configuration-based workaround is available; patching is the only definitive remediation.
The vulnerability was part of a broader Chrome stable channel update addressing 26 security issues, which received coverage from security news outlets including CyberSecurityNews, GBHackers, and CyberPress, primarily focusing on the two Critical use-after-free flaws (CVE-2026-84352 and CVE-2026-84353) rather than this lower-severity issue (CyberSecurityNews, GBHackers). The CIS also published an advisory noting multiple vulnerabilities in the Chrome update (CIS Advisory). Community reaction to this specific CVE has been minimal given its Low Chromium severity rating and lack of active exploitation.
Fix availability across major Linux distributions and their releases.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."