CVE-2026-84331: Google Chrome vulnerability
Incorrect authorization in Actor in Google Chrome prior to 152.0.7977.75 allowed a remote attacker who had compromised the renderer process to bypass web origin policy via a crafted HTML page. (Chromium security severity: Low)
Affected Software
Event History
Frequently Asked Questions
Who is realistically exposed to this issue?
Chrome users running versions earlier than 152.0.7977.75 are affected if an attacker has already compromised the browser's renderer process. The issue is not described as a standalone remote compromise of an otherwise uncompromised browser.
What does an attacker need to exploit it?
The attacker must first compromise the renderer process and then use a crafted HTML page. Under those conditions, they may bypass the web origin policy.
What should be done if patching cannot happen immediately?
The provided information identifies updating Chrome to 152.0.7977.75 or later as the available remediation boundary. No alternative mitigation or configuration workaround is specified.
How can I determine whether a Chrome installation is affected?
Check the installed Chrome version. Versions prior to 152.0.7977.75 are within the affected range described.