Monitor vulnerabilities like this one. Sign up free to get alerted when software you use is affected.
9.6

CVE-2026-84354: Google Chrome before version 152 may run code from malicious web page

CVE-2026-84354 · published 1 day ago
Summary

Older versions of Google Chrome (earlier than 152.0.7977.75) can be tricked by a carefully crafted web page to run code on the computer, bypassing Chrome’s normal safety sandbox. An attacker would need to convince a user to open the malicious page, often through a convincing email or message. Updating Chrome to the latest version fixes the problem; if you cannot update immediately, advise users not to click unknown links or open unexpected HTML files.

What to do
  • Update google chrome to version 152.0.7977.75 or later.
Affected software
VendorProductAffected versions
google chrome < 152.0.7977.75
Original advisory text
Incorrect authorization in FileSystem in Google Chrome prior to 152.0.7977.75 allowed a remote attacker leveraging social engineering to execute arbitrary code outside the sandbox via a crafted HTM...
Incorrect authorization in FileSystem in Google Chrome prior to 152.0.7977.75 allowed a remote attacker leveraging social engineering to execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: High)
Severity
9.6 Critical
Exploitation
EPSS <1%
Type
CWE-863Incorrect Authorization
Timeline
Published2 Sep 2026
Updated2 Sep 2026
First seen2 Sep 2026
Sources
CVE-2026-84354 · MITRE
Monitor software like this
Free during beta