Description
Incorrect authorization in TabStrip in Google Chrome prior to 152.0.7977.75 allowed a remote attacker who had compromised the renderer process and leveraged social engineering to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Medium)
Published: 2026-09-01
Score: n/a
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

A flaw in the TabStrip authorization logic allows a remote attacker who has already compromised the renderer process and uses social engineering to deliver a specially crafted web page to potentially execute code outside Chrome’s sandbox. The vulnerability stems from improper authorization checks, enabling the attacker to perform actions that are normally restricted to privileged code paths.

Affected Systems

The flaw affects Google Chrome on desktop platforms, specifically any installation of Chrome prior to revision 152.0.7977.75. Users running those versions are at risk until they upgrade.

Risk and Exploitability

Chromium labels the severity as Medium and lists it as a moderate impact. The EPSS score is not available, and the issue is not currently catalogued in the CISA KEV. Exploitation requires an attacker to first compromise the renderer process and then lures a user to open a maliciously crafted HTML page, so the overall likelihood is limited but plausible. Successful exploitation would give the attacker code execution outside the sandbox with the privileges of the renderer.

Generated by OpenCVE AI on September 2, 2026 at 03:26 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Update Chrome to version 152.0.7977.75 or later as soon as the stable channel release is available.
  • Avoid opening untrusted HTML files or clicking links that could present malicious content until the browser is updated.
  • Configure Chrome’s Site Isolation and related developer options to isolate renderer processes and reduce the impact of a compromised renderer.

Generated by OpenCVE AI on September 2, 2026 at 03:26 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 02 Sep 2026 03:45:00 +0000

Type Values Removed Values Added
Title Authorization bypass in Chrome TabStrip may allow remote code execution

Wed, 02 Sep 2026 02:45:00 +0000

Type Values Removed Values Added
First Time appeared Google
Google chrome
Vendors & Products Google
Google chrome

Wed, 02 Sep 2026 00:00:00 +0000

Type Values Removed Values Added
Description Incorrect authorization in TabStrip in Google Chrome prior to 152.0.7977.75 allowed a remote attacker who had compromised the renderer process and leveraged social engineering to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Medium)
Weaknesses CWE-863
References

cve-icon MITRE

Status: PUBLISHED

Assigner: Chrome

Published:

Updated: 2026-09-01T23:42:29.487Z

Reserved: 2026-09-01T16:20:40.675Z

Link: CVE-2026-84335

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-02T00:18:28.443

Modified: 2026-09-02T00:18:28.443

Link: CVE-2026-84335

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-02T03:30:06Z

Weaknesses