Junglewise Threat Intelligence

CVE-2026-84329: Google Chrome confused deputy in CredentialProvider on Windows

CVE-2026-84329 · Severity: medium · CVSS 5.3 · Published 2026-09-02

Technologies: Microsoft Windows, Google Chrome. Vendors: Microsoft, Google.

Executive brief

Google Chrome's credential provider component on Windows contains a logic flaw that could allow an attacker who has compromised the browser's rendering engine to leak sensitive user credentials or authentication data. An attacker would need to trick the user into visiting a malicious webpage after the renderer process has already been compromised, but successful exploitation could result in unauthorized access to user accounts and sensitive information.

Technical details

This vulnerability is a confused deputy issue in Chrome's CredentialProvider component on Windows, where the credential provider fails to properly validate requests from the renderer process. The vulnerability requires an attacker to have already compromised the renderer process and then deliver a crafted HTML page to trigger information disclosure. The attack vector is network-based but requires a precondition of prior renderer process compromise. Patches are available in Chrome version 152.0.7977.75 and later. The Chromium security team classified this as a low-severity issue despite the medium CVSS score.

Affected products

  • Google Chrome prior to 152.0.7977.75 on Windows

Timeline

  • 2026-09-02: disclosed
  • 2026-09-02: patched: Fixed in Chrome 152.0.7977.75

References

Related threats