Executive brief
A security vulnerability in Google Chrome's File System Access component could allow a remote attacker to bypass critical security boundaries. By using a specially crafted PDF file, an attacker who has already partially compromised the browser's rendering process could gain unauthorized access to data from other websites. This undermines 'site isolation,' a key defense that keeps data from different websites separate to protect user privacy and security.
Technical details
An improper access control vulnerability (CWE-284) exists in the File System Access API of Google Chrome. The flaw stems from insufficient policy enforcement which allows a remote attacker who has already compromised the renderer process to bypass site isolation mechanisms. This exploit is achieved by leveraging a specially crafted PDF file to access data across site boundaries. The vulnerability affects Google Chrome versions prior to 149.0.7827.155 across Windows, Mac, and Linux. Users are advised to update to the latest stable channel release to mitigate this risk.
Affected products
- Google Chrome prior to 149.0.7827.155
Timeline
- 2026-05-28: disclosed: Reported to Google by internal/external researchers.
- 2026-06-16: patched: Stable channel update released.
- 2026-06-17: advisory: NVD and Chrome release notes published.