SEPTEMBER 5, 2026
Live Feed
Back to database
Case File

CVE-2026-84358

MEDIUM · CVSS 4.2 EPSS 0.13%

Source: NVD + CISA KEV + EPSS · Published 2026-09-02 · Last synced 2026-09-05

CyberRota Analysis

AI-Generated

A vulnerability in Google Chrome prior to version 152.0.7977.75 allows remote attackers to exploit improper privilege management in the Downloads feature, enabling them to spoof the address bar through a malicious HTML page. This could lead to phishing attacks or the delivery of malicious content, posing a risk to users' security and privacy. Organizations using affected versions of Chrome should prioritize updating to mitigate potential exploitation.

CVE
CVE-2026-84358
Severity
MEDIUM
CVSS
4.2
EPSS
0.13%
Chrome

Original NVD Description

Improper privilege management in Downloads in Google Chrome prior to 152.0.7977.75 allowed a remote attacker who had compromised the renderer process to spoof address bar via a crafted HTML page. (Chromium security severity: Medium)

Related CVEs

Other vulnerabilities affecting the same vendor(s)