Junglewise Threat Intelligence

CVE-2026-84331: Google Chrome authorization bypass in Actor

CVE-2026-84331 · Severity: low · CVSS 3.1 · Published 2026-09-02

Technologies: Google Chrome. Vendors: Google.

Executive brief

Google Chrome contains an authorization flaw in a component called Actor that affects browser security. An attacker who has already compromised the browser's renderer process could craft a malicious webpage to bypass the web origin policy, potentially allowing unauthorized access across website boundaries. This could enable data theft or unauthorized actions on behalf of the user.

Technical details

The vulnerability is an incorrect authorization check in the Actor component of Google Chrome prior to version 152.0.7977.75. It allows a remote attacker with a compromised renderer process to bypass the same-origin policy through a crafted HTML page. The attack requires prior compromise of the renderer process, limiting the practical attack surface. Google has patched this vulnerability in Chrome 152.0.7977.75 and later. The Chromium project assigned this a Low security severity rating.

Affected products

  • Google Chrome prior to 152.0.7977.75

Timeline

  • 2026-09-02: disclosed
  • 2026-09-02: patched: Fixed in Chrome 152.0.7977.75

References

Related threats