PatchSiren cyber security CVE debrief
CVE-2026-84350 Google CVE debrief
A use after free vulnerability was reported in Google Chrome's TabStrip component prior to version 152.0.7977.75. This issue could allow a remote attacker to execute arbitrary code outside the sandbox via UI interaction, requiring social engineering tactics. The vulnerability has been assessed as having a high CVSS score of 8.8. The vulnerability affects Google Chrome versions prior to 152.0.7977.75. Limited information is available regarding potential exploits or attacks. Users should exercise caution when interacting with UI elements in Chrome to reduce the risk of exploitation. IT administrators responsible for managing Chrome deployments should prioritize patching to version 152.0.7977.75 or later.
- Vendor
- Product
- Chrome
- CVSS
- HIGH 8.8
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-09-02
- Original CVE updated
- 2026-09-03
- Advisory published
- 2026-09-02
- Advisory updated
- 2026-09-03
Who should care
Users of Google Chrome, particularly those who interact with the TabStrip component, should be aware of this vulnerability. IT administrators responsible for managing Chrome deployments should prioritize patching to version 152.0.7977.75 or later. Additionally, users should be cautious when interacting with UI elements in Chrome to reduce the risk of exploitation.
Technical summary
The vulnerability, CVE-2026-84350, is a use after free issue in Google Chrome's TabStrip component. It allows a remote attacker to execute arbitrary code outside the sandbox via UI interaction, requiring social engineering tactics. The CVSS score for this vulnerability is 8.8, indicating a high severity level. The issue was addressed in Google Chrome version 152.0.7977.75.
Defensive priority
Patching Google Chrome to version 152.0.7977.75 or later is strongly recommended to mitigate this vulnerability. Users should exercise caution when interacting with UI elements in Chrome to reduce the risk of exploitation.
Recommended defensive actions
- Patch Google Chrome to version 152.0.7977.75 or later
- Exercise caution when interacting with UI elements in Chrome
- Monitor for updates from Google regarding this vulnerability
Evidence notes
The CVE record and associated details were obtained from official sources, including the CVE Program and NVD. The vulnerability affects Google Chrome versions prior to 152.0.7977.75. Limited information is available regarding potential exploits or attacks.
Sources and references
Verified primary and authoritative sources
-
CVE-2026-84350 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-84350
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-84350 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-84350
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Source reference
Unverified legacy reference
URL: https://chromereleases.googleblog.com/2026/09/stable-channel-update-for-desktop.html
[email protected] - Release Notes, Vendor Advisory
-
Source reference
Unverified legacy reference
URL: https://issues.chromium.org/issues/513713427
[email protected] - Permissions Required
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.