CVE-2026-84359
vulnerability analysis and mitigation

Overview

CVE-2026-84359 is an information leak vulnerability in the Skia graphics library within Google Chrome that allows a remote attacker who has already compromised the renderer process to leak cross-origin data via a crafted HTML page. It affects all versions of Google Chrome prior to 152.0.7977.75. The vulnerability was reported internally by Google on 2026-05-17 and publicly disclosed on 2026-09-01 as part of a 26-fix stable channel update. It carries a CVSS v3.1 base score of 3.1 (Low), though Google rates its internal severity as High (Chrome Releases, Red Hat CVE).

Technical details

The root cause is classified under CWE-346 (Origin Validation Error) and CWE-200 (Exposure of Sensitive Information to an Unauthorized Actor), indicating that Skia — Chrome's 2D graphics rendering engine — fails to properly enforce cross-origin boundaries when rendering content. An attacker who has already achieved renderer process compromise can craft a malicious HTML page that triggers Skia to expose memory or pixel data belonging to cross-origin resources. Exploitation requires high attack complexity and user interaction (visiting a malicious page), and the attacker must have a pre-existing foothold in the renderer process, making this a post-exploitation information disclosure rather than a standalone initial access vector (Red Hat CVE, Chrome Releases).

Impact

Successful exploitation results in the disclosure of cross-origin data from the browser's rendering memory, impacting confidentiality only — there is no integrity or availability impact. An attacker with a compromised renderer could use this flaw to exfiltrate sensitive content rendered by other origins (e.g., session tokens, page content, or images from authenticated sites), potentially enabling further lateral movement or credential theft. The scope is limited to the browser process and does not directly result in system-level compromise (Red Hat CVE, Feedly).

Exploitability

There is no public proof-of-concept exploit and no evidence of in-the-wild exploitation as of the time of disclosure (Feedly). The EPSS score is approximately 0.0014 (0.14%), reflecting a low probability of exploitation in the near term. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. Exploitation is further constrained by the requirement that the attacker must have already compromised the renderer process, significantly raising the bar for abuse.

Mitigation and workarounds

Google has released a fix in Chrome stable channel version 152.0.7977.75 (Linux) and 152.0.7977.75/.76 (Windows and Mac). Users and administrators should update Google Chrome to version 152.0.7977.75 or later immediately. No configuration-based workarounds are available; patching is the only remediation. Enterprise administrators should verify deployment via policy management tools and monitor Google's Chrome Security Page for further advisories (Chrome Releases, Microsoft MSRC).

Community reactions

The September 2026 Chrome stable update, which included this fix among 26 security patches, received broad coverage from security news outlets. Publications such as CyberSecurityNews, GBHackers, and The Daily Tech Feed highlighted the update's two critical use-after-free flaws (CVE-2026-84353 and CVE-2026-84352) as the headline items, with CVE-2026-84359 noted as one of several High-severity fixes. The CIS also issued an advisory noting that multiple vulnerabilities in the update could allow for arbitrary code execution in certain scenarios (CyberSecurityNews, CIS Advisory).

Additional resources

Linux Distribution fix status

Fix availability across major Linux distributions and their releases.

Debian

Fixed

bookworm

chromium: 152.0.7977.75-1~deb12u1

Fixed

sid

libskia: 146.20260602~git.3476902+dfsg-4

Fixed

trixie

chromium: 152.0.7977.75-1~deb13u1

Fixed

RHEL / CentOS

Fixed

RHEL 8

webkit2gtk3.src

Affected

RHEL 9

:appstream:webkit2gtk3-0:2.54.0-1.el9_8.src

Fixed

RHEL 10

firefox.src

Affected

SourceThis report was generated using AI

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management