CVE-2026-84335

Google · Chrome

An incorrect authorization vulnerability in the TabStrip component of Google Chrome allows remote attackers to potentially escape the sandbox and execute arbitrary code via a crafted HTML page.

Executive summary

A high-severity authorization flaw in Google Chrome allows remote attackers to achieve sandbox escape and arbitrary code execution through social engineering and a compromised renderer process.

Vulnerability

The vulnerability exists due to incorrect authorization logic in the TabStrip component. An unauthenticated remote attacker can exploit this by enticing a user to interact with a malicious HTML page, triggering a renderer process compromise to escape the browser sandbox.

Business impact

This vulnerability poses a significant risk to organizational endpoints, as successful exploitation enables attackers to bypass critical browser security boundaries. Given the CVSS score of 8.3, the impact is severe, potentially leading to full system compromise, data exfiltration, or the deployment of malware within the user environment.

Remediation

Immediate Action: Update all instances of Google Chrome to version 152.0.7977.75 or later immediately to incorporate the vendor-supplied authorization fix.

Proactive Monitoring: Review endpoint security logs for anomalous browser behavior or unexpected process execution patterns originating from the Google Chrome renderer process.

Compensating Controls: Deploy endpoint detection and response (EDR) solutions to identify and block suspicious child processes spawned by web browsers, and consider using browser isolation technologies for high-risk users.

Exploitation status

Public Exploit Available: No

Analyst recommendation

The severity of this vulnerability, combined with its potential for arbitrary code execution outside the browser sandbox, necessitates an immediate patching cycle across all managed systems. Security teams should prioritize the deployment of the latest Chrome version to eliminate this high-risk attack vector and prevent potential system-wide compromise.

More Google CVEs

Sources