Threat Brief — 2026-09-04 — Chromium ships 20-CVE patch batch
Microsoft's MSRC feed has catalogued 20 Chromium-originated CVEs that Edge inherits from its upstream Chromium base. The batch spans use-after-free conditions in WebRTC, Browser, TabStrip, and Shared Tab Groups; a GPU buffer overflow; a V8 uninitialized-resource flaw; and a heavy cluster of incorrect/missing-authorization bugs across Autofill, FileSystem, Navigation, SiteSettings, Chromoting, and other components. No active exploitation is indicated in the advisory text. Separately, France's CNIL issued a €500,000 fine against Hôpital privé de la Loire after a breach exposed data belonging to 727,000 patients and relatives — a regulatory signal for healthcare data-protection posture.
Top items
- Chromium/Edge September 2026 patch batch — 20 CVEs across browser core components. The set includes memory-safety bugs (use-after-free in WebRTC CVE-2026-84347, Browser CVE-2026-84349, TabStrip CVE-2026-84350, Shared Tab Groups CVE-2026-84353; buffer overflow in GPU CVE-2026-84351; uninitialized resource in V8 CVE-2026-84326) and a broad swath of authorization-bypass flaws (Autofill CVE-2026-84327, Actor CVE-2026-84331, SiteSettings CVE-2026-84332, Chromoting CVE-2026-84334, TabStrip CVE-2026-84335, FileSystem CVE-2026-84328 and CVE-2026-84354, Navigation CVE-2026-84355), plus a confused-deputy issue in CredentialProvider CVE-2026-84329, an information leak in MediaCapture CVE-2026-84348 and Skia CVE-2026-84359, UI misrepresentation in FullScreen CVE-2026-84356, improper input validation in Omnibox CVE-2026-84357, and improper privilege management in Downloads CVE-2026-84358. Affects Google Chrome and all Chromium-based Edge builds. No public exploit or in-the-wild exploitation is evidenced in the source advisories. (src: MSRC – CVE-2026-84359)
- CNIL fines French hospital €500,000 after breach exposes 727,000 individuals. France's data protection authority penalised Hôpital privé de la Loire for inadequate safeguards on patient and relative data. The scale of exposure (727,000 records) and the size of the fine are notable for healthcare-sector data-protection risk. (src: BleepingComputer)
Themes
Authorization-bypass cluster in Chromium. At least 8 of the 20 CVEs in this batch are incorrect-authorization or missing-authorization issues spread across distinct browser subsystems (Autofill, FileSystem, Navigation, SiteSettings, Chromoting, TabStrip, Actor, Downloads). The breadth suggests a systemic permission-enforcement problem rather than a single-component regression — worth tracking whether future Chromium hardening addresses the pattern holistically.
Memory-safety issues persist in high-value surfaces. Use-after-free conditions in WebRTC, Browser, TabStrip, and Shared Tab Groups, alongside a GPU buffer overflow and a V8 uninitialized-resource bug, reinforce that browser memory-surface attack area remains active despite sandboxing and mitigation investments.
