SEPTEMBER 15, 2026
Live Feed
Back to database
Case File

CVE-2026-84325

CRITICAL · CVSS 9.8 EPSS 0.25%

Source: NVD + CISA KEV + EPSS · Published 2026-09-02 · Last synced 2026-09-15

CyberRota Analysis

AI-Generated

Improper input validation in the DataTransfer component of Google Chrome prior to version 152.0.7977.75 allows remote attackers to exploit this vulnerability through social engineering tactics, potentially bypassing system access restrictions via co-installed applications. Organizations using affected versions of Chrome should prioritize patching to mitigate the risk of unauthorized access and data compromise.

CVE
CVE-2026-84325
Severity
CRITICAL
CVSS
9.8
EPSS
0.25%
Chrome

Original NVD Description

Improper input validation in DataTransfer in Google Chrome prior to 152.0.7977.75 allowed a remote attacker leveraging social engineering to bypass system access restrictions via a co-installed app. (Chromium security severity: High)

Related CVEs

Other vulnerabilities affecting the same vendor(s)