
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-84357 is an improper input validation vulnerability in the Omnibox component of Google Chrome that allows a remote attacker leveraging social engineering to bypass the web origin policy via crafted network traffic. It affects all versions of Google Chrome prior to 152.0.7977.75 and was reported by Google on June 12, 2026, with the fix disclosed on September 1, 2026. The vulnerability carries a CVSS v3.1 base score of 6.5 (Medium) (Feedly, Chrome Releases).
The vulnerability is rooted in insufficient input validation (CWE-20) within Chrome's Omnibox (address bar) component, leading to an origin validation error (CWE-346). An attacker can craft malicious network traffic and use social engineering to trick a user into interacting with it, causing Chrome to incorrectly evaluate or trust a web origin and bypass the same-origin policy. Exploitation requires user interaction (e.g., visiting a malicious page or clicking a crafted link) but no special privileges or authentication. The Chromium issue tracker references bug ID 523208474 (Chrome Releases, Feedly).
Successful exploitation allows an attacker to bypass web origin policy, potentially enabling unauthorized cross-origin requests or actions that should be restricted by browser security boundaries. The primary impact is on integrity (CVSS integrity impact: High), with no direct confidentiality or availability impact. This could allow an attacker to perform actions on behalf of a user across origins, potentially leading to data manipulation, unauthorized API calls, or session-related attacks within the browser context (Feedly).
There is no public proof-of-concept exploit and no evidence of in-the-wild exploitation as of the time of disclosure (Feedly). The EPSS score is approximately 0.159%, indicating a low probability of exploitation in the near term. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. Exploitation is not automatable and requires user interaction via social engineering.
Google has released a fix in Chrome 152.0.7977.75 (Linux) and 152.0.7977.75/.76 (Windows and Mac). Users and administrators should update Google Chrome to version 152.0.7977.75 or later immediately. Additionally, organizations should educate users about social engineering tactics and suspicious links to reduce the risk of exploitation. No configuration-based workaround is available; patching is the only remediation (Chrome Releases, Feedly).
The vulnerability was part of a broader Chrome 152 security update that patched 26 vulnerabilities, including two Critical-rated use-after-free flaws, which drew significant media attention. Security outlets including CyberSecurityNews, GBHackers, and The Daily Tech Feed covered the release, focusing primarily on the critical memory bugs rather than CVE-2026-84357 specifically (CyberSecurityNews, GBHackers). CIS also issued an advisory noting that multiple vulnerabilities in the update could allow for arbitrary code execution (CIS Advisory).
Fix availability across major Linux distributions and their releases.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."