Improper Privilege Management in Google Chrome Affects Address Bar Spoofing
CVE-2026-84358

Currently unrated

Key Information:

Vendor

Google

Status
Vendor
CVE Published:
1 September 2026

What is CVE-2026-84358?

Vulnerability in Google Chrome's Downloads has been identified as a flaw in privilege management, allowing a remote attacker who has compromised the renderer process to manipulate the address bar using a specially crafted HTML page. This issue poses significant risks, particularly in scenarios where users may be misled by the displayed URL, potentially leading them to malicious sites. Users are encouraged to update to the latest version to mitigate this vulnerability.

Affected Version(s)

Chrome 152.0.7977.75

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.