
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-84359 is an information leak vulnerability in the Skia graphics library within Google Chrome that allows a remote attacker who has already compromised the renderer process to leak cross-origin data via a crafted HTML page. It affects all versions of Google Chrome prior to 152.0.7977.75. The vulnerability was reported internally by Google on 2026-05-17 and publicly disclosed on 2026-09-01 as part of a 26-fix stable channel update. It carries a CVSS v3.1 base score of 3.1 (Low), though Google rates its internal severity as High (Chrome Releases, Red Hat CVE).
The root cause is classified under CWE-346 (Origin Validation Error) and CWE-200 (Exposure of Sensitive Information to an Unauthorized Actor), indicating that Skia — Chrome's 2D graphics rendering engine — fails to properly enforce cross-origin boundaries when rendering content. An attacker who has already achieved renderer process compromise can craft a malicious HTML page that triggers Skia to expose memory or pixel data belonging to cross-origin resources. Exploitation requires high attack complexity and user interaction (visiting a malicious page), and the attacker must have a pre-existing foothold in the renderer process, making this a post-exploitation information disclosure rather than a standalone initial access vector (Red Hat CVE, Chrome Releases).
Successful exploitation results in the disclosure of cross-origin data from the browser's rendering memory, impacting confidentiality only — there is no integrity or availability impact. An attacker with a compromised renderer could use this flaw to exfiltrate sensitive content rendered by other origins (e.g., session tokens, page content, or images from authenticated sites), potentially enabling further lateral movement or credential theft. The scope is limited to the browser process and does not directly result in system-level compromise (Red Hat CVE, Feedly).
There is no public proof-of-concept exploit and no evidence of in-the-wild exploitation as of the time of disclosure (Feedly). The EPSS score is approximately 0.0014 (0.14%), reflecting a low probability of exploitation in the near term. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. Exploitation is further constrained by the requirement that the attacker must have already compromised the renderer process, significantly raising the bar for abuse.
Google has released a fix in Chrome stable channel version 152.0.7977.75 (Linux) and 152.0.7977.75/.76 (Windows and Mac). Users and administrators should update Google Chrome to version 152.0.7977.75 or later immediately. No configuration-based workarounds are available; patching is the only remediation. Enterprise administrators should verify deployment via policy management tools and monitor Google's Chrome Security Page for further advisories (Chrome Releases, Microsoft MSRC).
The September 2026 Chrome stable update, which included this fix among 26 security patches, received broad coverage from security news outlets. Publications such as CyberSecurityNews, GBHackers, and The Daily Tech Feed highlighted the update's two critical use-after-free flaws (CVE-2026-84353 and CVE-2026-84352) as the headline items, with CVE-2026-84359 noted as one of several High-severity fixes. The CIS also issued an advisory noting that multiple vulnerabilities in the update could allow for arbitrary code execution in certain scenarios (CyberSecurityNews, CIS Advisory).
Fix availability across major Linux distributions and their releases.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."