CVE-2026-84356: UI misrepresentation in FullScreen
Chromium: CVE-2026-84356 UI misrepresentation in FullScreen
Other sources
This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see Google Chrome Releases for more information.
— Microsoft
UI misrepresentation in FullScreen in Google Chrome prior to 152.0.7977.75 allowed a remote attacker to spoof address bar via a crafted HTML page. (Chromium security severity: Low)
— MITRE
Credit
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 152.0.7977.75 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 152.0.4191.62 - Upgrade
Upgrade
Chromium / Google Chrome (as used by Microsoft Edge)to a version that resolves this vulnerability.Fixed in 152.0.7977.75
Event History
Peer vulnerabilities
Found alongside the following vulnerabilities.
- CVE-2026-84353
- CVE-2026-84352
- CVE-2026-84354
- CVE-2026-84359
- CVE-2026-84357
- CVE-2026-84324
- CVE-2026-84349
- CVE-2026-84326
- CVE-2026-84333
- CVE-2026-84351
- CVE-2026-84325
- CVE-2026-84328
- CVE-2026-84347
- CVE-2026-84323
- CVE-2026-84355
- CVE-2026-84358
- CVE-2026-84332
- CVE-2026-84330
- CVE-2026-84334
- CVE-2026-84348
- CVE-2026-84335
- CVE-2026-84327
- CVE-2026-84329
- CVE-2026-84350
- CVE-2026-84331
Frequently Asked Questions
What does an attacker need to do to exploit this issue?
The attacker needs to get a user to load a crafted HTML page. The issue affects Chrome's FullScreen UI handling and can be used to spoof the address bar.
Which Chrome versions should be remediated?
Google Chrome versions prior to 152.0.7977.75 are affected. Update Chrome to 152.0.7977.75 or later.