Junglewise Threat Intelligence

CVE-2026-14052: Google Chrome insufficient policy enforcement in FileSystem

CVE-2026-14052 · Severity: info · CVSS 0 · Published 2026-06-30

Technologies: Google Chrome. Vendors: Google.

Executive brief

A vulnerability in Google Chrome's FileSystem component could allow a malicious website to bypass security restrictions. By convincing a user to visit a specially crafted webpage, an attacker could gain unauthorized access to files or data that should normally be protected by the browser's access controls. This could lead to a minor breach of privacy or unauthorized data manipulation within the browser's sandboxed environment.

Technical details

An insufficient policy enforcement vulnerability exists in the FileSystem API of Google Chrome. The flaw resides in how the browser manages discretionary access control (DAC) for file system resources. A remote attacker can exploit this by hosting a malicious HTML page and enticing a user to visit it. Successful exploitation allows the attacker to bypass intended access restrictions within the FileSystem context. This issue was addressed in Chrome version 150.0.7871.47. Google has classified this with a 'Low' severity rating.

Affected products

  • Google Chrome prior to 150.0.7871.47

Timeline

  • 2026-06-30: disclosed
  • 2026-06-30: patched
  • 2026-06-30: advisory

References

Related threats