CVE-2026-84353: Use after free in Shared Tab Groups
Chromium: CVE-2026-84353 Use after free in Shared Tab Groups
Other sources
This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see Google Chrome Releases for more information.
— Microsoft
Use after free in Shared Tab Groups in Google Chrome on on Android prior to 152.0.7977.75 allowed a remote attacker leveraging social engineering to execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Critical)
— MITRE
Credit
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 152.0.7977.75 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 152.0.4191.62 - Upgrade
Upgrade
Microsoft Edge (Chromium-based)to a version that resolves this vulnerability.Fixed in 152.0.7977.75
Event History
Peer vulnerabilities
Found alongside the following vulnerabilities.
- CVE-2026-84352
- CVE-2026-84354
- CVE-2026-84359
- CVE-2026-84357
- CVE-2026-84324
- CVE-2026-84349
- CVE-2026-84326
- CVE-2026-84333
- CVE-2026-84351
- CVE-2026-84325
- CVE-2026-84328
- CVE-2026-84347
- CVE-2026-84323
- CVE-2026-84355
- CVE-2026-84358
- CVE-2026-84332
- CVE-2026-84330
- CVE-2026-84334
- CVE-2026-84348
- CVE-2026-84335
- CVE-2026-84327
- CVE-2026-84329
- CVE-2026-84356
- CVE-2026-84350
- CVE-2026-84331
Frequently Asked Questions
What does an attacker need to exploit this issue?
The attacker needs to convince a user to interact with a crafted HTML page. The issue is described as remotely exploitable through social engineering.
What is the potential impact of successful exploitation?
A successful attacker could execute arbitrary code outside Chrome's sandbox. Chromium rates the issue as Critical.
Which Chrome installations are affected?
Google Chrome on Android versions prior to 152.0.7977.75 are affected. The provided information does not state whether Shared Tab Groups must be enabled or used for exploitation.