Sceawere

Vulnerability Detail

CVE-2026-84358UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

Chrome Downloads Improper Privilege Management

Vulnerability Metadata

Severity
Medium
Score / CVSS
4.2
Creation Date
1d ago
Vendor
Google
Product
Chrome
Attack Type
Improper privilege management
Vector String
CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:L/I:N/A:L
Attack Complexity
HIGH

Narrative and Response

Description

Improper privilege management in Downloads in Google Chrome prior to 152.0.7977.75 allowed a remote attacker who had compromised the renderer process to spoof address bar via a crafted HTML page. (Chromium security severity: Medium)

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "4.2",
  "pubDate": "2026-09-02T00:18:29.737Z",
  "pubdate": "2026-09-02T00:18:29.737Z",
  "executiveSummary": "This vulnerability involves improper privilege management within the Downloads component of Google Chrome, affecting versions prior to 152.0.7977.75.\nThe flaw permits a remote attacker who has successfully compromised the renderer process to conduct address bar spoofing through the use of a specifically crafted HTML page.\nAddress bar spoofing is a critical security concern as it facilitates phishing and social engineering attacks by deceiving users into believing they are interacting with a legitimate, trusted domain.\nThe vulnerability resides within the browser's privilege model, where insufficient restrictions allow a compromised renderer—which should ideally be sandboxed—to manipulate user interface elements that are typically reserved for higher-privilege processes.\nSuccessful exploitation requires the attacker to first gain control of the renderer process, typically through a separate exploit chain targeting a web-based entry point.\nThe risk implication is high, as the ability to spoof the address bar effectively bypasses the browser's identity verification mechanisms, making it nearly impossible for a standard user to distinguish between authentic and malicious content.\nThere are no authentication requirements for this exploitation path beyond the prerequisite renderer compromise.",
  "technicalDetails": "The vulnerability originates from a breakdown in the security boundary between the renderer process and the browser process, specifically concerning the Downloads component's handling of navigation and UI updates.\nIn Chromium architecture, the renderer process is intended to be highly restricted; however, improper privilege management allows an attacker who has achieved remote code execution within the renderer to influence state information usually reserved for the browser process.\nThe exploit flow begins when a user is directed to a malicious HTML page controlled by the attacker. Upon execution of the attacker's payload within the context of the renderer, the attacker leverages the lack of robust validation in the Downloads sub-system to force the browser to render UI elements that do not correspond to the actual origin of the content.\nSpecifically, the manipulation allows the renderer to trigger a state where the address bar reflects an arbitrary, trusted domain while the actual content being displayed originates from an attacker-controlled origin.\nBecause the Downloads component interfaces with the browser's download manager, it maintains specific permissions to interact with the file system and navigation events. The vulnerability indicates that the interface through which the renderer communicates with the Downloads manager does not sufficiently verify or sanitize the parameters passed to the address bar controller.\nBy bypassing these integrity checks, the attacker can manipulate the URL display logic. When the user perceives the spoofed URL, they may be prompted to download malicious files or enter credentials, believing they are interacting with the spoofed, trusted entity.\nThis behavior constitutes a privilege escalation within the browser's internal object model, as the renderer successfully exerts influence over the browser's 'Chrome' UI, a process space it should have no influence over according to the principle of least privilege.\nThe impact is significant, as the browser's address bar serves as the primary root of trust for users during web navigation. By subverting this element, the attacker effectively nullifies the visual security feedback loop intended to protect users from deceptive content."
}
CVE-2026-84358: Chrome Downloads Improper Privilege Management (MEDIUM Severity, CVSS: 4.2) - Sceawere