Junglewise Threat Intelligence

CVE-2026-84357: Google Chrome Omnibox web origin bypass via improper input validation

CVE-2026-84357 · Severity: medium · CVSS 6.5 · Published 2026-09-02

Technologies: Google Chrome. Vendors: Google.

Executive brief

Google Chrome's address bar (Omnibox) contains an input validation flaw that allows attackers to bypass web origin policies through crafted network traffic combined with social engineering. An exploit could trick users into accepting or navigating to spoofed or malicious websites, potentially leading to credential theft or malware infection.

Technical details

The vulnerability is an improper input validation flaw in Chrome's Omnibox component that allows bypass of web origin policy restrictions. An attacker can craft malicious network traffic and use social engineering tactics to exploit this flaw, potentially allowing a remote attacker to spoof or bypass origin protections. The attack requires user interaction and social engineering. The fix is available in Chrome version 152.0.7977.75 and later. Chromium classified this as high severity.

Affected products

  • Google Chrome prior to 152.0.7977.75

Timeline

  • 2026-09-02: disclosed: CVE-2026-84357 published
  • 2026-09-02: patched: Fix released in Chrome 152.0.7977.75

References

Related threats