Junglewise Threat Intelligence

CVE-2026-78959: Google Chrome improper case sensitivity handling in FileSystem

CVE-2026-78959 · Severity: medium · CVSS 6.5 · Published 2026-08-25

Technologies: Google Chrome. Vendors: Google.

Executive brief

Google Chrome's FileSystem component improperly handles case sensitivity checks, allowing an attacker to bypass file access restrictions through a specially crafted HTML page. An attacker could exploit this via social engineering to trick users into visiting a malicious webpage, potentially gaining unauthorized access to files on the user's system that should have been restricted.

Technical details

This vulnerability involves improper handling of case sensitivity in Chrome's FileSystem API, where the browser fails to correctly validate file path case distinctions. An attacker can craft a malicious HTML page that, when visited by a user, exploits this flaw to bypass system access restrictions and access files outside the intended sandbox. The attack vector is network-based and relies on social engineering to deliver the malicious page to the victim. The vulnerability affects Chrome versions prior to 152.0.7977.65 and has been addressed in Chrome 152 stable release.

Affected products

  • Google Chrome prior to 152.0.7977.65

Timeline

  • 2026-08-25: disclosed
  • 2026-08-25: patched: Fixed in Chrome 152.0.7977.65

References

Related threats