Description
Incorrect authorization in TabStrip in Google Chrome prior to 152.0.7977.75 allowed a remote attacker who had compromised the renderer process and leveraged social engineering to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Medium)
Published: 2026-09-01
Score: 8.3 High
EPSS: < 1% Very Low
KEV: No
Impact: Remote Code Execution
Action: Immediate Patch
AI Analysis

Impact

A flaw in the TabStrip authorization logic allows a remote attacker who has already compromised the renderer process and uses social engineering to deliver a specially crafted web page to potentially execute code outside Chrome’s sandbox. The vulnerability stems from improper authorization checks, enabling the attacker to perform actions that are normally restricted to privileged code paths.

Affected Systems

The flaw affects Google Chrome on desktop platforms, specifically any installation of Chrome prior to revision 152.0.7977.75. Users running those versions are at risk until they upgrade.

Risk and Exploitability

The vulnerability has a CVSS score of 8.3, indicating a high impact. The EPSS score is < 1%, indicating a very low likelihood of exploitation. Exploitation requires an attacker to first compromise the renderer process and then lure a user to open a maliciously crafted HTML page, so the overall likelihood is limited but plausible. Successful exploitation would give the attacker code execution outside the sandbox with the privileges of the renderer.

Generated by OpenCVE AI on September 4, 2026 at 02:22 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Update Chrome to version 152.0.7977.75 or later as soon as the stable channel release is available.
  • Avoid opening untrusted HTML files or clicking links that could present malicious content until the browser is updated.
  • Configure Chrome’s Site Isolation and related developer options to isolate renderer processes and reduce the impact of a compromised renderer.

Generated by OpenCVE AI on September 4, 2026 at 02:22 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Debian DLA Debian DLA DLA-4771-1 chromium security update
Debian DSA Debian DSA DSA-6482-1 chromium security update
History

Fri, 04 Sep 2026 00:15:00 +0000

Type Values Removed Values Added
Title chromium-browser: Google Chrome TabStrip: Arbitrary Code Execution via Crafted HTML Page
Weaknesses CWE-272
References
Metrics threat_severity

None

threat_severity

Moderate


Thu, 03 Sep 2026 17:15:00 +0000

Type Values Removed Values Added
CPEs cpe:2.3:a:google:chrome:*:*:*:*:*:*:*:*

Wed, 02 Sep 2026 14:00:00 +0000

Type Values Removed Values Added
Title Authorization bypass in Chrome TabStrip may allow remote code execution

Wed, 02 Sep 2026 10:30:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 8.3, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:H'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Wed, 02 Sep 2026 03:45:00 +0000

Type Values Removed Values Added
Title Authorization bypass in Chrome TabStrip may allow remote code execution

Wed, 02 Sep 2026 02:45:00 +0000

Type Values Removed Values Added
First Time appeared Google
Google chrome
Vendors & Products Google
Google chrome

Wed, 02 Sep 2026 00:00:00 +0000

Type Values Removed Values Added
Description Incorrect authorization in TabStrip in Google Chrome prior to 152.0.7977.75 allowed a remote attacker who had compromised the renderer process and leveraged social engineering to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Medium)
Weaknesses CWE-863
References

cve-icon MITRE

Status: PUBLISHED

Assigner: Chrome

Published:

Updated: 2026-09-03T03:55:33.617Z

Reserved: 2026-09-01T16:20:40.675Z

Link: CVE-2026-84335

cve-icon Vulnrichment

Updated: 2026-09-02T09:43:56.634Z

cve-icon NVD

Status : Analyzed

Published: 2026-09-02T00:18:28.443

Modified: 2026-09-03T17:09:46.783

Link: CVE-2026-84335

cve-icon Redhat

Severity : Moderate

Publid Date: 2026-09-01T23:42:29Z

Links: CVE-2026-84335 - Bugzilla

cve-icon OpenCVE Enrichment

Updated: 2026-09-04T02:30:13Z

Weaknesses