CVE-2026-84325

Google · Chrome

Google Chrome contains an improper input validation flaw in the DataTransfer component that allows remote attackers to bypass system access restrictions via social engineering.

Executive summary

A critical vulnerability in Google Chrome allows remote attackers to bypass system access restrictions, posing a significant risk to user data and system integrity.

Vulnerability

The vulnerability exists due to improper input validation within the DataTransfer component of Google Chrome. This flaw allows an unauthenticated remote attacker to bypass system access restrictions when combined with social engineering and a co-installed application.

Business impact

The exploitation of this vulnerability carries a severe risk, as it allows for unauthorized access to system resources and potential compromise of user data. With a CVSS score of 9.8, this flaw is categorized as critical, indicating that successful execution could lead to full system compromise, data theft, or unauthorized control over the browser environment. Organizations relying on Chrome for business operations face significant reputational and operational risks if these access restrictions are bypassed.

Remediation

Immediate Action: Update all installations of Google Chrome to version 152.0.7977.75 or later immediately to incorporate the security fixes.

Proactive Monitoring: Monitor endpoint logs for unusual application behavior or unauthorized attempts to access system-level data via browser-based processes.

Compensating Controls: Implement robust email filtering and user awareness training to mitigate the risk of social engineering attacks that are required to facilitate this exploit.

Exploitation status

Public Exploit Available: No

Analyst recommendation

Given the critical CVSS severity and the nature of the flaw, organizations must prioritize patching all Chrome instances across their environment. Users and administrators should ensure that automatic updates are enabled and verify that the browser has been successfully upgraded to the patched version to prevent potential exploitation of this access bypass mechanism.

More Google CVEs

Sources