Executive brief
Google Chrome's file system access controls contained an authorization flaw that could allow remote attackers to bypass system access restrictions. An attacker could exploit this vulnerability by tricking users into visiting a specially crafted web page, potentially gaining unauthorized access to local files and system resources.
Technical details
This vulnerability is an incorrect authorization flaw in Chrome's FileSystem component. The issue allows a remote attacker leveraging social engineering (via a crafted HTML page) to bypass file system access restrictions that should prevent unauthorized access. The attack requires user interaction—the victim must visit a malicious webpage. Chrome 152.0.7977.65 and later resolve this issue. The vulnerability was assigned medium severity (CVSS 4.3) and has not been observed being exploited in the wild.
Affected products
- Google Chrome prior to 152.0.7977.65
Timeline
- 2026-08-25: disclosed
- 2026-08-25: patched: Chrome 152.0.7977.65 released