Junglewise Threat Intelligence

CVE-2026-84325: Google Chrome improper input validation in DataTransfer

CVE-2026-84325 · Severity: critical · CVSS 9.8 · Published 2026-09-02

Technologies: Google Chrome. Vendors: Google.

Executive brief

Google Chrome, the widely-used web browser, contains an improper input validation flaw in its DataTransfer component that could allow an attacker to bypass system access restrictions. An attacker could exploit this through social engineering combined with a co-installed application to circumvent security controls, potentially leading to unauthorized access to sensitive data or system resources.

Technical details

This vulnerability is an improper input validation issue in the DataTransfer component of Google Chrome versions prior to 152.0.7977.75. The flaw allows a remote attacker to bypass system access restrictions by leveraging social engineering tactics combined with a co-installed application. The vulnerability requires user interaction and relies on a secondary installed application on the victim's system to be effective. This is a network-exploitable issue with a CVSS score of 9.8, reflecting its high potential impact on confidentiality and integrity.

Affected products

  • Google Chrome prior to 152.0.7977.75

Timeline

  • 2026-09-02: disclosed
  • 2026-09-02: patched: Fixed in Chrome 152.0.7977.75

References

Related threats