PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-84350 Google CVE debrief

A use after free vulnerability was reported in Google Chrome's TabStrip component prior to version 152.0.7977.75. This issue could allow a remote attacker to execute arbitrary code outside the sandbox via UI interaction, requiring social engineering tactics. The vulnerability has been assessed as having a high CVSS score of 8.8. The vulnerability affects Google Chrome versions prior to 152.0.7977.75. Limited information is available regarding potential exploits or attacks. Users should exercise caution when interacting with UI elements in Chrome to reduce the risk of exploitation. IT administrators responsible for managing Chrome deployments should prioritize patching to version 152.0.7977.75 or later.

Vendor
Google
Product
Chrome
CVSS
HIGH 8.8
CISA KEV
Not listed in stored evidence
Original CVE published
2026-09-02
Original CVE updated
2026-09-03
Advisory published
2026-09-02
Advisory updated
2026-09-03

Who should care

Users of Google Chrome, particularly those who interact with the TabStrip component, should be aware of this vulnerability. IT administrators responsible for managing Chrome deployments should prioritize patching to version 152.0.7977.75 or later. Additionally, users should be cautious when interacting with UI elements in Chrome to reduce the risk of exploitation.

Technical summary

The vulnerability, CVE-2026-84350, is a use after free issue in Google Chrome's TabStrip component. It allows a remote attacker to execute arbitrary code outside the sandbox via UI interaction, requiring social engineering tactics. The CVSS score for this vulnerability is 8.8, indicating a high severity level. The issue was addressed in Google Chrome version 152.0.7977.75.

Defensive priority

Patching Google Chrome to version 152.0.7977.75 or later is strongly recommended to mitigate this vulnerability. Users should exercise caution when interacting with UI elements in Chrome to reduce the risk of exploitation.

Recommended defensive actions

  • Patch Google Chrome to version 152.0.7977.75 or later
  • Exercise caution when interacting with UI elements in Chrome
  • Monitor for updates from Google regarding this vulnerability

Evidence notes

The CVE record and associated details were obtained from official sources, including the CVE Program and NVD. The vulnerability affects Google Chrome versions prior to 152.0.7977.75. Limited information is available regarding potential exploits or attacks.

Sources and references

Verified primary and authoritative sources

  • CVE-2026-84350 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2026-84350

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2026-84350 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2026-84350

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.