Description
Improper input validation in DataTransfer in Google Chrome prior to 152.0.7977.75 allowed a remote attacker leveraging social engineering to bypass system access restrictions via a co-installed app. (Chromium security severity: High)
Published: 2026-09-01
Score: n/a
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

Improper input validation in Chrome’s DataTransfer component allows a remote attacker to bypass system access restrictions through a co‑installed application, enabling unauthorized actions that would normally be denied. The weakness is a classic input validation flaw categorized as CWE‑20 and is considered high severity by Chromium security. The attacker can cause the browser to treat privileged data as non‑privileged, which may facilitate further exploitation.

Affected Systems

Affected systems are users running any version of Google Chrome before 152.0.7977.75. No specific patches are listed in the input, but the advisory indicates that the issue is fixed in the 152.0.7977.75 release.

Risk and Exploitability

The CVE is rated high severity and appears in a major browser, so the potential impact is significant. EPSS data is unavailable, and the vulnerability is not currently listed in the CISA Known Exploited Vulnerabilities catalog. The likely attack vector involves social engineering, such as phishing or malicious web content that lures a user to install a co‑installed app that can exploit the flaw.

Generated by OpenCVE AI on September 2, 2026 at 04:03 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Update Chrome to version 152.0.7977.75 or later or a newer release that contains the fix.
  • Disable or uninstall any co‑installed applications that interact with data transfer functionality until the vendor releases a safe update.
  • If your organization manages Chrome via policy, configure the browser to block or warn about untrusted app installations and limit DataTransfer access to trusted contexts.

Generated by OpenCVE AI on September 2, 2026 at 04:03 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 02 Sep 2026 04:30:00 +0000

Type Values Removed Values Added
Title DataTransfer Input Validation Vulnerability in Chrome Enables Privilege Escalation

Wed, 02 Sep 2026 02:15:00 +0000

Type Values Removed Values Added
First Time appeared Google
Google chrome
Vendors & Products Google
Google chrome

Wed, 02 Sep 2026 00:00:00 +0000

Type Values Removed Values Added
Description Improper input validation in DataTransfer in Google Chrome prior to 152.0.7977.75 allowed a remote attacker leveraging social engineering to bypass system access restrictions via a co-installed app. (Chromium security severity: High)
Weaknesses CWE-20
References

cve-icon MITRE

Status: PUBLISHED

Assigner: Chrome

Published:

Updated: 2026-09-01T23:42:27.627Z

Reserved: 2026-09-01T16:20:12.629Z

Link: CVE-2026-84325

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-02T00:18:27.340

Modified: 2026-09-02T00:18:27.340

Link: CVE-2026-84325

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-02T04:15:05Z

Weaknesses
  • CWE-20

    Improper Input Validation