Junglewise Threat Intelligence

CVE-2026-11258: Google Chrome DAC bypass in File System Access

CVE-2026-11258 · Severity: info · Published 2026-06-05

Technologies: Google Chrome. Vendors: Google.

Executive brief

A security issue in Google Chrome's File System Access component could allow a malicious website to bypass security controls. To exploit this, an attacker must trick a user into performing specific mouse or keyboard actions on a specially crafted webpage. If successful, the attacker could gain unauthorized access to files that should normally be protected by the browser's security boundaries.

Technical details

An inappropriate implementation vulnerability exists in the File System Access API of Google Chrome prior to version 149.0.7827.53. The flaw allows a remote attacker to bypass discretionary access controls (DAC) by inducing a user to perform specific UI gestures on a malicious HTML page. This bypass could potentially lead to unauthorized file system operations that the browser is intended to restrict. The vulnerability is categorized by Chromium as Low severity and requires user interaction to be successfully exploited. The issue is addressed in the stable channel update for Windows, Mac, and Linux.

Affected products

  • Google Chrome prior to 149.0.7827.53

Timeline

  • 2026-06-02: patched: Chrome 149.0.7827.53 released to stable channel.
  • 2026-06-05: disclosed: CVE-2026-11258 published.

References

Related threats