CVE-2026-84325

EUVD-2026-69738
Improper input validation in DataTransfer in Google Chrome prior to 152.0.7977.75 allowed a remote attacker leveraging social engineering to bypass system access restrictions via a co-installed app. (Chromium security severity: High)
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
ChromeCNA
9.8 CRITICAL
NETWORK
LOW
NONE
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Base Score
CVSS 3.x
EPSS Score
Percentile: 5.37%
Early Detection
Affected products identified ahead of NVD analysis through intelligence sources.
VendorProductVersionSource
googlechrome
𝑥
< 152.0.7977.75
CNA
Debian logo
Debian Releases
Debian Product
Codename
chromium
bookworm
vulnerable
bookworm (security)
vulnerable
forky
vulnerable
sid
vulnerable
trixie
vulnerable
trixie (security)
vulnerable
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
chromium-browser
jammy
not-affected
noble
not-affected
resolute
not-affected