Executive brief
Google Chrome's FileSystem component has an authorization bypass vulnerability that allows remote attackers to access restricted files on a user's system by tricking them into viewing a specially crafted webpage. This could enable attackers to steal sensitive documents, configuration files, or other protected data stored on the computer.
Technical details
The vulnerability is an incorrect authorization flaw in Chrome's FileSystem component that permits a remote attacker to bypass access restrictions through social engineering. The attack requires crafting a malicious HTML page that, when viewed by a user, exploits improper authorization checks. No authentication or elevated privileges are required on the attacker's side—only that the victim visit the malicious page. An attacker can read or access files that should be protected by the system. The vulnerability has been patched in Chrome 152.0.7977.65 and later versions.
Affected products
- Google Chrome prior to 152.0.7977.65
Timeline
- 2026-08-25: disclosed
- 2026-08-25: patched