Skip to content
GoogleCVE-2026-84335

Google Chrome: improper authorization

High8.3CVE-2026-84335 · Published Sep 2, 2026 · updated Sep 3, 2026

Incorrect authorization in TabStrip in Google Chrome prior to 152.0.7977.75 allowed a remote attacker who had compromised the renderer process and leveraged social engineering to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Medium)

Google advisory

Affected versions

PackageAffectedFixed in
Chrome
Product
>= 152.0.7977.75, < 152.0.7977.75152.0.7977.75
Details and references

More Google advisories

All Google
Advisory
Google Chrome: use after free
Critical9.6Sep 2
Google Chrome: use after free
Critical9.6Sep 2
Google Chrome: improper authorization
Critical9.6Sep 2
Google Chrome: improper authorization
Low3.1Sep 2
Google Chrome: spoofing
Medium4.3Sep 2
Google Chrome: improper input validation
Medium6.5Sep 2

Critical advisories by email

Wednesdays: the week’s critical and high advisories in the AI and data stack, with the fixed versions. Only in weeks that have some.

Double opt-in. Unsubscribe any time.