Junglewise Threat Intelligence

CVE-2026-79143: Google Chrome incorrect authorization in FileSystem

CVE-2026-79143 · Severity: medium · CVSS 4.3 · Published 2026-08-25

Technologies: Google Chrome. Vendors: Google.

Executive brief

Google Chrome's file system access controls contained an authorization flaw that could allow remote attackers to bypass system access restrictions. An attacker could exploit this vulnerability by tricking users into visiting a specially crafted web page, potentially gaining unauthorized access to local files and system resources.

Technical details

This vulnerability is an incorrect authorization flaw in Chrome's FileSystem component. The issue allows a remote attacker leveraging social engineering (via a crafted HTML page) to bypass file system access restrictions that should prevent unauthorized access. The attack requires user interaction—the victim must visit a malicious webpage. Chrome 152.0.7977.65 and later resolve this issue. The vulnerability was assigned medium severity (CVSS 4.3) and has not been observed being exploited in the wild.

Affected products

  • Google Chrome prior to 152.0.7977.65

Timeline

  • 2026-08-25: disclosed
  • 2026-08-25: patched: Chrome 152.0.7977.65 released

References

Related threats