Skip to main content
CVE Vulnerability Database
Vulnerability Database/CVE-2026-84332

CVE-2026-84332: Chrome SiteSettings Auth Bypass Vulnerability

CVE-2026-84332 is an authentication bypass flaw in Chrome SiteSettings that lets attackers evade system access restrictions through malicious HTML pages. This post explains its impact, affected versions, and mitigation steps.

Published:

CVE-2026-84332 Overview

CVE-2026-84332 is an incorrect authorization vulnerability [CWE-863] in the SiteSettings component of Google Chrome. Versions of Chrome prior to 152.0.7977.75 fail to properly enforce access restrictions when handling site permission logic. A remote attacker can exploit this flaw by convincing a user to visit a crafted HTML page, bypassing system access restrictions within the browser. Google's Chromium team assigned this issue a Medium severity rating. The vulnerability requires user interaction and does not impact confidentiality or availability, but it enables high-impact integrity violations.

Critical Impact

A remote attacker can bypass browser-enforced site access restrictions via a crafted HTML page, allowing manipulation of permission state without user consent.

Affected Products

  • Google Chrome versions prior to 152.0.7977.75 on desktop platforms
  • Chromium-based browsers inheriting the vulnerable SiteSettings implementation
  • All operating systems supported by the Chrome Stable channel (Windows, macOS, Linux)

Discovery Timeline

  • 2026-09-02 - CVE-2026-84332 published to the National Vulnerability Database
  • 2026-09-02 - Last updated in NVD database

Technical Details for CVE-2026-84332

Vulnerability Analysis

The vulnerability resides in Chrome's SiteSettings subsystem, which manages per-origin permissions for capabilities such as camera, microphone, geolocation, notifications, and file access. The authorization logic incorrectly evaluates access decisions for certain site-scoped operations. As a result, a remote origin can perform actions that should be gated by explicit user consent or origin-based restrictions.

The classification under CWE-863 indicates the code performs an authorization check, but the check uses incorrect conditions or misidentifies the acting principal. The CVSS vector reports a high integrity impact with no confidentiality or availability impact, consistent with unauthorized state modification rather than data disclosure or crash conditions.

Root Cause

The root cause is a flawed authorization decision within SiteSettings when validating whether a given origin is permitted to invoke or influence a protected operation. Chromium's tracker entry Issue #514489238 documents the internal defect. The check does not correctly reconcile the requesting origin with the effective policy scope, allowing a crafted page to slip past the guard.

Attack Vector

Exploitation is network-based and requires user interaction. An attacker hosts a crafted HTML page and lures the target to load it in a vulnerable Chrome build. The page issues requests or DOM interactions that trigger the flawed authorization path in SiteSettings. The attacker then manipulates permission or setting state that should be restricted, undermining the browser's site isolation and consent model. No verified public proof-of-concept code is available at the time of publication. Refer to the Google Chrome Stable Update for vendor context.

Detection Methods for CVE-2026-84332

Indicators of Compromise

  • Chrome browser processes running versions earlier than 152.0.7977.75 after the patch release date
  • Unexpected changes to site permission state (camera, microphone, geolocation) without corresponding user prompts
  • Outbound connections from user endpoints to attacker-controlled domains immediately preceding permission-state anomalies

Detection Strategies

  • Inventory installed Chrome versions across the fleet and flag any host running a build below 152.0.7977.75.
  • Correlate web proxy logs with endpoint telemetry to identify users visiting untrusted HTML content followed by browser configuration changes.
  • Review Chrome enterprise policy audit logs for anomalous SiteSettings transitions that lack a preceding user consent event.

Monitoring Recommendations

  • Enable Chrome Enterprise reporting to centralize browser version and extension telemetry for continuous compliance checks.
  • Alert on endpoints where Chrome auto-update is disabled or stalled, since these hosts will remain exposed.
  • Track user reports of unexpected site permission grants or notifications as a behavioral signal of exploitation attempts.

How to Mitigate CVE-2026-84332

Immediate Actions Required

  • Update Google Chrome to version 152.0.7977.75 or later on all desktop endpoints.
  • Force a browser restart after the update to ensure the patched binary is loaded into memory.
  • Verify that Chrome auto-update mechanisms (GoogleUpdate on Windows, Keystone on macOS, package manager on Linux) are functioning and not blocked by policy.

Patch Information

Google released the fix in the Chrome Stable channel at version 152.0.7977.75. Deployment details are documented in the Google Chrome Stable Update release notes. Enterprise administrators should push the update through Chrome Browser Cloud Management, Group Policy, or their existing software distribution platform. The corresponding upstream fix is tracked in Chromium Issue #514489238.

Workarounds

  • Restrict browsing to trusted sites using Chrome Enterprise policies such as URLBlocklist and URLAllowlist until patching completes.
  • Disable or restrict sensitive site permissions (camera, microphone, geolocation, notifications) through the DefaultGeolocationSetting and related enterprise policies.
  • Deploy web filtering to block newly registered or low-reputation domains that could host crafted exploitation pages.
bash
# Verify installed Chrome version on Linux endpoints
google-chrome --version

# Windows: query the installed version via registry
reg query "HKLM\SOFTWARE\Google\Chrome\BLBeacon" /v version

# macOS: query the bundle version
defaults read /Applications/Google\ Chrome.app/Contents/Info CFBundleShortVersionString

Disclaimer: This content was generated using AI. While we strive for accuracy, please verify critical information with official sources.

Default Legacy - Prefooter | Experience the World’s Most Advanced Cybersecurity Platform

Experience the Most Advanced Cybersecurity Platform

See how the world’s most intelligent, autonomous cybersecurity platform can protect your organization today and into the future.