CVE-2026-84326: Google Chrome vulnerability
Published Sep 1, 2026
·Updated
Uninitialized resource in V8 in Google Chrome prior to 152.0.7977.75 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: High)
Affected Software
1 affected component
Google Chrome<152.0.7977.75
Event History
Sep 1, 2026
CVE Published
via MITRE·11:42 PM
Data Sourced
via MITRE·11:42 PM
DescriptionWeakness
Frequently Asked Questions
1
Who is exposed to this vulnerability?
Users of Google Chrome versions earlier than 152.0.7977.75 are exposed when they visit or render a crafted HTML page. The described code execution is limited to the browser sandbox.
2
What does an attacker need to exploit it?
The attacker needs to cause the target to process a crafted HTML page remotely. The available information does not identify any additional prerequisites, such as local access or authentication.
3
How can I determine whether a system is affected?
Check the installed Google Chrome version. Versions prior to 152.0.7977.75 are affected according to the advisory.