CVE-2026-84356
vulnerability analysis and mitigation

Overview

CVE-2026-84356 is a UI misrepresentation vulnerability in the FullScreen feature of Google Chrome that allows a remote attacker to spoof the browser's address bar via a crafted HTML page. It affects all versions of Google Chrome prior to 152.0.7977.75. The vulnerability was reported by researcher Francesco Topol (k4tedu) on April 18, 2026, and publicly disclosed on September 1, 2026, when Google released Chrome 152.0.7977.75 (Chrome Releases). It carries a CVSS v3.1 base score of 4.3 (Medium) and is rated Low severity by Chromium's internal security classification (Red Hat CVE).

Technical details

The vulnerability is classified under CWE-1021 (Improper Restriction of Rendered UI Layers or Frames) and CWE-451 (User Interface Misrepresentation of Critical Information), reflecting a flaw in how Chrome renders the browser UI during FullScreen mode (Red Hat CVE). When a user enters full-screen mode via a crafted HTML page, the browser fails to properly restrict or display the address bar, allowing an attacker-controlled page to present a fraudulent URL or UI element in place of the legitimate browser chrome. Exploitation requires user interaction — specifically, a victim must visit and interact with the attacker's crafted page — and no authentication or elevated privileges are required on the attacker's side. The attack vector is network-based, and the technical impact is limited to integrity (UI spoofing), with no confidentiality or availability impact (Red Hat CVE).

Impact

Successful exploitation allows an unauthenticated remote attacker to deceive users into believing they are visiting a legitimate website by spoofing the browser's address bar while in full-screen mode, potentially facilitating phishing attacks or credential harvesting. The impact is limited to integrity — there is no direct data exfiltration, code execution, or denial of service. However, the social engineering potential is significant, as users may enter sensitive information (e.g., passwords, payment details) into attacker-controlled pages that appear to be trusted sites (Red Hat CVE, Chrome Releases).

Exploitability

There is no public proof-of-concept exploit and no evidence of in-the-wild exploitation at this time (Red Hat CVE). The vulnerability is not listed in CISA's Known Exploited Vulnerabilities (KEV) catalog, and NVD's SSVC assessment confirms exploitation is currently "none" and the vulnerability is not automatable. The EPSS score is approximately 0.162%, indicating a low probability of exploitation in the near term. Exploitation requires user interaction, further reducing the practical risk.

Exploitation steps

  1. Craft a malicious HTML page: The attacker creates an HTML page that programmatically triggers full-screen mode (e.g., using the Fullscreen API via element.requestFullscreen()) and renders a fake browser UI — including a spoofed address bar displaying a trusted domain (e.g., https://bank.com).
  2. Lure the victim: The attacker distributes the malicious page link via phishing email, social media, or malicious advertisement, enticing the victim to click and visit the page.
  3. Trigger full-screen mode: Upon page load or user interaction (e.g., a button click), the page enters full-screen mode, exploiting the UI misrepresentation flaw in Chrome's FullScreen handling to obscure or replace the legitimate browser address bar.
  4. Deceive the user: The victim sees a convincing fake browser UI with a spoofed URL, believing they are on a legitimate site, and may enter credentials or sensitive information into attacker-controlled form fields.
  5. Harvest data: The attacker collects submitted credentials or other sensitive data from the fake page (Chrome Releases, Red Hat CVE).

Indicators of compromise

  • Network: Unexpected outbound connections from user endpoints to unfamiliar domains after visiting a site that triggered full-screen mode; HTTP requests to pages that immediately invoke the Fullscreen API.
  • Logs: Browser history or proxy logs showing visits to suspicious URLs that subsequently triggered full-screen transitions; user-reported phishing incidents involving full-screen browser spoofing.
  • Process: Chrome processes running with full-screen flags initiated by non-standard web pages; JavaScript console errors or warnings related to Fullscreen API usage on unexpected domains.

Mitigation and workarounds

Google has patched this vulnerability in Chrome version 152.0.7977.75 (Linux) and 152.0.7977.75/.76 (Windows and Mac); users should update immediately via Chrome's built-in update mechanism (Chrome Releases). Microsoft has also issued guidance for Edge users affected by the underlying Chromium vulnerability (Microsoft MSRC). As a precautionary measure, users should be advised to press Esc to exit full-screen mode when visiting unfamiliar sites and to verify the URL in the address bar before entering sensitive information. No configuration-based workaround is available; patching is the only definitive remediation.

Community reactions

The vulnerability was part of a broader Chrome stable channel update addressing 26 security issues, which received coverage from security news outlets including CyberSecurityNews, GBHackers, and CyberPress, primarily focusing on the two Critical use-after-free flaws (CVE-2026-84352 and CVE-2026-84353) rather than this lower-severity issue (CyberSecurityNews, GBHackers). The CIS also published an advisory noting multiple vulnerabilities in the Chrome update (CIS Advisory). Community reaction to this specific CVE has been minimal given its Low Chromium severity rating and lack of active exploitation.

Additional resources

Linux Distribution fix status

Fix availability across major Linux distributions and their releases.

Debian

Fixed

bookworm

chromium: 152.0.7977.75-1~deb12u1

Fixed

sid

chromium: 152.0.7977.75-1

Fixed

trixie

chromium: 152.0.7977.75-1~deb13u1

Fixed

SourceThis report was generated using AI

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management