CVE-2026-84331: Incorrect authorization in Actor
Chromium: CVE-2026-84331 Incorrect authorization in Actor
Other sources
Incorrect authorization in Actor in Google Chrome prior to 152.0.7977.75 allowed a remote attacker who had compromised the renderer process to bypass web origin policy via a crafted HTML page. (Chromium security severity: Low)
— MITRE
This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see Google Chrome Releases for more information.
— Microsoft
Credit
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 152.0.7977.75 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 152.0.4191.62 - Upgrade
Upgrade
Chromium/Google Chrome (Chromium-based, including Microsoft Edge)to a version that resolves this vulnerability.Fixed in 152.0.7977.75
Event History
Peer vulnerabilities
Found alongside the following vulnerabilities.
- CVE-2026-84353
- CVE-2026-84352
- CVE-2026-84354
- CVE-2026-84359
- CVE-2026-84357
- CVE-2026-84324
- CVE-2026-84349
- CVE-2026-84326
- CVE-2026-84333
- CVE-2026-84351
- CVE-2026-84325
- CVE-2026-84328
- CVE-2026-84347
- CVE-2026-84323
- CVE-2026-84355
- CVE-2026-84358
- CVE-2026-84332
- CVE-2026-84330
- CVE-2026-84334
- CVE-2026-84348
- CVE-2026-84335
- CVE-2026-84327
- CVE-2026-84329
- CVE-2026-84356
- CVE-2026-84350
Frequently Asked Questions
Who is realistically exposed to this issue?
Chrome users running versions earlier than 152.0.7977.75 are affected if an attacker has already compromised the browser's renderer process. The issue is not described as a standalone remote compromise of an otherwise uncompromised browser.
What does an attacker need to exploit it?
The attacker must first compromise the renderer process and then use a crafted HTML page. Under those conditions, they may bypass the web origin policy.
What should be done if patching cannot happen immediately?
The provided information identifies updating Chrome to 152.0.7977.75 or later as the available remediation boundary. No alternative mitigation or configuration workaround is specified.
How can I determine whether a Chrome installation is affected?
Check the installed Chrome version. Versions prior to 152.0.7977.75 are within the affected range described.