CVE-2026-84329CWE-441

CVE-2026-84329

Medium · published September 2, 2026

CVSS v3.1
5.3
EPSS
0%
Percentile
6.5
In the wild
Unconfirmed
What it is

Confused deputy in CredentialProvider in Google Chrome on on Windows prior to 152.0.7977.75 allowed a remote attacker who had compromised the renderer process to leak sensitive information via a crafted HTML page. (Chromium security severity: Low)

The record
Technical detail
CVSS v3.1
5.3 · MEDIUM
Vector
CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:N/A:N
CVSS v4.0
Not supplied
EPSS
0.00169 · 6.5th percentile
Weakness
CWE-441 · Unintended Proxy or Intermediary ('Confused Deputy')
Published
2026-09-02T04:18Z
Affected products (1)
ProductVersionsFixed in
google/chrome< 152.0.7977.75152.0.7977.75
References (2)
EPSS history
Timeline
  • 03 SEP 03:32Z
    EPSS moved — → 0%
    epss
  • 01 SEP 23:42Z
    Confused deputy in CredentialProvider in Google Chrome on on Windows prior to 152.0.7977.75 allowed a remote attacker who had compromised the renderer process…
    cvelistv5