Monitor vulnerabilities like this one.
Sign up free to get alerted when software you use is affected.
9.6
CVE-2026-84354: Google Chrome before version 152 may run code from malicious web page
CVE-2026-84354 · published 1 day ago
Summary
Older versions of Google Chrome (earlier than 152.0.7977.75) can be tricked by a carefully crafted web page to run code on the computer, bypassing Chrome’s normal safety sandbox. An attacker would need to convince a user to open the malicious page, often through a convincing email or message. Updating Chrome to the latest version fixes the problem; if you cannot update immediately, advise users not to click unknown links or open unexpected HTML files.
What to do
- Update google chrome to version 152.0.7977.75 or later.
Affected software
| Vendor | Product | Affected versions |
|---|---|---|
| chrome | < 152.0.7977.75 |
Original advisory text
Incorrect authorization in FileSystem in Google Chrome prior to 152.0.7977.75 allowed a remote attacker leveraging social engineering to execute arbitrary code outside the sandbox via a crafted HTM...
Incorrect authorization in FileSystem in Google Chrome prior to 152.0.7977.75 allowed a remote attacker leveraging social engineering to execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: High)
Severity
9.6
Critical
Exploitation
EPSS <1%
Type
CWE-863Incorrect Authorization
Timeline
Published2 Sep 2026
Updated2 Sep 2026
First seen2 Sep 2026
Monitor software like this
Free during beta