CVE-2026-84325 describes an improper input validation vulnerability in the DataTransfer component of Google Chrome prior to version 152.0.7977.75. A remote attacker could exploit this flaw through social engineering techniques to bypass system access restrictions via a co-installed application. The vulnerability has been rated High severity by the Chromium security team. The fix was included in the Chrome stable channel update for desktop released in September 2026. Users are advised to update to Chrome 152.0.7977.75 or later to mitigate the risk. The attack vector requires user interaction through social engineering, adding a layer of complexity to exploitation. The issue was tracked internally via Chromium issue tracker reference 553117928.