Monitor vulnerabilities like this one. Sign up free to get alerted when software you use is affected.
9.8

CVE-2026-84325: Google Chrome <152 can be tricked to bypass limits

CVE-2026-84325 · published 1 day ago
Summary

Versions of Google Chrome released before 152 may let a malicious website convince a user to install a companion app that then sidesteps normal security checks. This could let an attacker gain access to parts of the computer they shouldn't reach. Update Chrome to the latest version and avoid installing unknown apps or extensions, especially those suggested by unexpected emails or messages.

What to do
  • Update google chrome to version 152.0.7977.75 or later.
Affected software
VendorProductAffected versions
google chrome < 152.0.7977.75
Original advisory text
Improper input validation in DataTransfer in Google Chrome prior to 152.0.7977.75 allowed a remote attacker leveraging social engineering to bypass system access restrictions via a co-installed app...
Improper input validation in DataTransfer in Google Chrome prior to 152.0.7977.75 allowed a remote attacker leveraging social engineering to bypass system access restrictions via a co-installed app. (Chromium security severity: High)
Severity
9.8 Critical
Exploitation
EPSS <1%
Type
CWE-20Improper Input Validation
Timeline
Published2 Sep 2026
Updated2 Sep 2026
First seen2 Sep 2026
Sources
CVE-2026-84325 · MITRE
Monitor software like this
Free during beta