Junglewise Threat Intelligence

CVE-2026-84350: Google Chrome use-after-free in TabStrip

CVE-2026-84350 · Severity: high · CVSS 8.8 · Published 2026-09-02

Technologies: Google Chrome. Vendors: Google.

Executive brief

Google Chrome contains a use-after-free memory vulnerability in the TabStrip component that allows attackers to execute arbitrary code outside the browser's sandbox protection. Exploitation requires social engineering to trick a user into interacting with a malicious UI element, potentially leading to complete compromise of the user's system and data.

Technical details

A use-after-free vulnerability exists in the TabStrip component of Google Chrome prior to version 152.0.7977.75. The vulnerability can be triggered through UI interaction combined with social engineering, allowing a remote attacker to escape the sandbox and execute arbitrary code with the privileges of the Chrome process. Exploitation requires user interaction and is not a network-based attack. The vulnerability has been patched in Chrome 152.0.7977.75 and later.

Affected products

  • Google Chrome prior to 152.0.7977.75

Timeline

  • 2026-09-02: disclosed

References

Related threats