[NEW] [high] Google Chrome: Multiple Vulnerabilities
An attacker can exploit multiple vulnerabilities in Google Chrome to execute arbitrary code, escalate privileges, bypass security measures, disclose sensitive information, conduct spoofing attacks, manipulate data, or cause Denial of Service conditions.
CSIRTS triage
- What
- Multiple vulnerabilities in Google Chrome enable arbitrary code execution, privilege escalation, security bypass, information disclosure, spoofing, data manipulation, and Denial of Service.
- Who is affected
- All users of Google Chrome.
- Urgency
- High severity with code execution risk; patches should be applied immediately.
- Action
- Update Google Chrome to the latest version.
AI-assisted analysis generated from the source advisory — verify against the original.
⚡ Watch Chrome
Get an email when a new Chrome advisory drops — max one per day, one-click unsubscribe.
Details
Original advisory: https://wid.cert-bund.de/portal/wid/securityadvisory?name=WID-SEC-2026-3133
Referenced CVEs
Same CVEs, other sources
How other CERTs, PSIRTs and databases cover the vulnerabilities in this advisory.
- unknownGoogle Chrome Multiple Vulnerabilitieshkcert
- lowCVE-2026-84359: Information leak in Skia in Google Chrome prior to 152.0.7977.75 allowed a remote attacker who…nvd
- mediumCVE-2026-84358: Improper privilege management in Downloads in Google Chrome prior to 152.0.7977.75 allowed a r…nvd
- mediumCVE-2026-84357: Improper input validation in Omnibox in Google Chrome prior to 152.0.7977.75 allowed a remote …nvd
- mediumCVE-2026-84356: UI misrepresentation in FullScreen in Google Chrome prior to 152.0.7977.75 allowed a remote at…nvd
- lowCVE-2026-84355: Incorrect authorization in Navigation in Google Chrome prior to 152.0.7977.75 allowed a remote…nvd
- criticalCVE-2026-84354: Incorrect authorization in FileSystem in Google Chrome prior to 152.0.7977.75 allowed a remote…nvd
- criticalCVE-2026-84353: Use after free in Shared Tab Groups in Google Chrome on on Android prior to 152.0.7977.75 allo…nvd
- criticalCVE-2026-84352: Use after free in WebGL in Google Chrome on on Android prior to 152.0.7977.75 allowed a remote…nvd
- highCVE-2026-84351: Buffer overflow in GPU in Google Chrome on on Windows prior to 152.0.7977.75 allowed a remote …nvd
- highCVE-2026-84350: Use after free in TabStrip in Google Chrome prior to 152.0.7977.75 allowed a remote attacker l…nvd
- highCVE-2026-84349: Use after free in Browser in Google Chrome prior to 152.0.7977.75 allowed a remote attacker wh…nvd
Recent advisories for Google Chrome
A cluster of recent advisories against the same product widens the attack surface — attackers routinely chain freshly published CVEs on one product, so review these together.
- highexploited[UPDATE] [high] Google Chrome / Microsoft Edge: Vulnerability enables code executioncert-bund · 2026-09-02
- medium[UPDATE] [medium] Google Chrome / Microsoft Edge: Multiple Vulnerabilitiescert-bund · 2026-09-02
- highexploited[UPDATE] [high] Google Chrome and Microsoft Edge: Multiple Vulnerabilitiescert-bund · 2026-09-02
- highexploited[UPDATE] [high] Google Chrome and Microsoft Edge: Multiple Vulnerabilities enable code executioncert-bund · 2026-09-02
- highexploited[UPDATE] [high] Google Chrome / Microsoft Edge: Multiple Vulnerabilitiescert-bund · 2026-09-02
- medium[UPDATE] [medium] Google Chrome / Microsoft Edge: Multiple Vulnerabilities enable unspecified attackcert-bund · 2026-09-02
More from CERT-Bund (BSI) Security Advisories
- high[NEW] [high] IBM i: Multiple Vulnerabilities2026-09-03
- medium[NEW] [medium] Sonatype Nexus Repository Manager: Multiple Vulnerabilities Enable Denial of Service2026-09-03
- high[NEW] [high] BigBlueButton: Multiple Vulnerabilities2026-09-03
- medium[UPDATE] [medium] Linux Kernel: Multiple vulnerabilities2026-09-03
- medium[NEW] [medium] Red Hat Enterprise Linux (libsolv, aardvark-dns): Multiple vulnerabilities2026-09-03