CVE-2026-84327: Google Google Chrome (Android) vulnerability
Published Sep 1, 2026
·Updated
Incorrect authorization in Autofill in Google Chrome on on Android prior to 152.0.7977.75 allowed a remote attacker leveraging social engineering to obtain sensitive information via a crafted HTML page. (Chromium security severity: Low)
Affected Software
1 affected component
Google Google Chrome (Android)<152.0.7977.75
Event History
Sep 1, 2026
CVE Published
via MITRE·11:42 PM
Data Sourced
via MITRE·11:42 PM
DescriptionWeakness
Frequently Asked Questions
1
Which Chrome installations are affected?
Google Chrome on Android versions prior to 152.0.7977.75 are affected. The provided information does not identify affected desktop versions.
2
What must an attacker do to exploit this issue?
The attacker needs to use a crafted HTML page and rely on social engineering. Successful exploitation can allow the attacker to obtain sensitive information through Chrome Autofill.
3
How should organizations mitigate the issue?
Update Chrome on Android to version 152.0.7977.75 or later. The provided information does not specify an alternative workaround if updating is not immediately possible.