CVE-2026-84357: Improper input validation in Omnibox
Chromium: CVE-2026-84357 Improper input validation in Omnibox
Other sources
Improper input validation in Omnibox in Google Chrome prior to 152.0.7977.75 allowed a remote attacker leveraging social engineering to bypass web origin policy via crafted network traffic. (Chromium security severity: High)
— MITRE
This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see Google Chrome Releases for more information.
— Microsoft
Credit
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 152.0.7977.75 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 152.0.4191.62 - Upgrade
Upgrade
Google Chrome / Chromium-based browsers (Edge ingesting Chromium)to a version that resolves this vulnerability.Fixed in 152.0.7977.75 - Compensating control
Because exploitation may involve crafted network traffic leveraging social engineering to bypass web origin policy, restrict exposure to untrusted navigation/network paths as a compensating control until the Chromium-based browser is updated to 152.0.7977.75.
Event History
Peer vulnerabilities
Found alongside the following vulnerabilities.
- CVE-2026-84353
- CVE-2026-84352
- CVE-2026-84354
- CVE-2026-84359
- CVE-2026-84324
- CVE-2026-84349
- CVE-2026-84326
- CVE-2026-84333
- CVE-2026-84351
- CVE-2026-84325
- CVE-2026-84328
- CVE-2026-84347
- CVE-2026-84323
- CVE-2026-84355
- CVE-2026-84358
- CVE-2026-84332
- CVE-2026-84330
- CVE-2026-84334
- CVE-2026-84348
- CVE-2026-84335
- CVE-2026-84327
- CVE-2026-84329
- CVE-2026-84356
- CVE-2026-84350
- CVE-2026-84331
Frequently Asked Questions
Which Chrome versions are affected?
Google Chrome versions prior to 152.0.7977.75 are affected. Updating to 152.0.7977.75 or later remediates the issue.
What would an attacker need to exploit this issue?
The attacker would need to use crafted network traffic and successfully leverage social engineering against the target. The reported impact is a bypass of the web origin policy.