Junglewise Threat Intelligence

CVE-2026-78985: Google Chrome incorrect reference resolution in FileSystem

CVE-2026-78985 · Severity: critical · CVSS 9.6 · Published 2026-08-25

Technologies: Google Chrome. Vendors: Google.

Executive brief

Chrome's FileSystem component contained a flaw in how it resolves file references, allowing an attacker to break out of the browser's security sandbox. By crafting a malicious HTML page and using social engineering to trick a user into visiting it, an attacker could execute arbitrary code with the full privileges of the user's system. This could lead to complete system compromise, data theft, or installation of malware.

Technical details

This vulnerability is an incorrect reference resolution flaw in Chrome's FileSystem implementation, classified as a sandbox escape. The affected component fails to properly validate or resolve file system references, allowing a remote attacker to bypass sandbox restrictions. The attack requires a crafted HTML page and social engineering to convince a user to visit the malicious site; no authentication or additional user interaction beyond the initial page visit is needed. A successful exploit enables arbitrary code execution outside the Chrome sandbox with user-level privileges. The vulnerability was fixed in Chrome 152.0.7977.65 (Windows/Mac) and 152.0.7977.64 (Linux).

Affected products

  • Google Chrome prior to 152.0.7977.65

Timeline

  • 2026-08-25: disclosed
  • 2026-08-25: patched: Fixed in Chrome 152.0.7977.65/64

References

Related threats