DIRAS TAKE
Urgent: this is a network-triggered, no-interaction remote code execution (no authentication and no user interaction required), so update immediately to the fixed build 152.0.7977.75 or later.
What is CVE-2026-84324?
Remote attackers can execute arbitrary code in Google Chrome via a use-after-free in the Proxy component (CVE-2026-84324). The flaw impacts Chrome 152.x releases prior to 152.0.7977.75 and can be triggered by crafted network traffic; an attacker only needs network access to deliver the malicious traffic. Successful exploitation can run code outside the browser sandbox, risking confidentiality, integrity, and availability of the host running the affected Chrome version. The weakness is classified as CWE-416 (Use After Free).
Vector CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H
Which versions of Google Chrome are affected?
| BRANCH | AFFECTED | FIXED |
|---|---|---|
| 152.x | 152.0.7977.75 – before 152.0.7977.75 | 152.0.7977.75 |
Is CVE-2026-84324 being exploited?
There are no public reports of exploitation as of 2026-09-30.
How to fix CVE-2026-84324
- Update Google Chrome to 152.0.7977.75 or later.
- Enable automatic updates to ensure future fixes are applied promptly.
- If you cannot update immediately, restrict network exposure of affected clients and block untrusted traffic where possible.
- Follow Google’s security guidance and monitor endpoints for signs of compromise.
Frequently asked questions
Is CVE-2026-84324 being actively exploited?
No public reports of exploitation have been published as of 2026-09-30.
Which Chrome versions are affected by CVE-2026-84324?
Chrome 152.x releases before 152.0.7977.75 are affected by CVE-2026-84324.
Is there a patch for CVE-2026-84324?
Yes. Google fixed the vulnerability in Chrome version 152.0.7977.75; update Chrome to that build or later.
Does CVE-2026-84324 require authentication?
No. CVE-2026-84324 can be triggered over the network without authentication or user interaction.
References
- nvd.nist.gov/vuln/detail/CVE-2026-84324
- cve.org/CVERecord?id=CVE-2026-84324
- chromereleases.googleblog.com/2026/09/stable-channel-update-for-desktop.html
- issues.chromium.org/issues/533534913
- All Google CVEs on CVE Radar
- CVEs published in September 2026