Executive brief
Google Chrome's FileSystem component contained an out of bounds memory read vulnerability that allowed remote attackers to read sensitive data outside the browser's security sandbox. An attacker could exploit this flaw by tricking users into visiting a malicious webpage, potentially exposing memory contents and bypassing Chrome's sandbox protection mechanism.
Technical details
This vulnerability is an out of bounds read in Chrome's FileSystem component that allows information disclosure from memory outside the sandbox. The attack vector requires social engineering to persuade a user to visit a crafted HTML page; no authentication or special user privilege is required, only user interaction. A successful exploit enables an attacker to read memory beyond intended boundaries, potentially accessing sensitive data protected by the sandbox. The vulnerability was patched in Chrome 152.0.7977.65 and later versions.
Affected products
- Google Chrome prior to 152.0.7977.65
Timeline
- 2026-08-25: disclosed
- 2026-08-25: patched: Fixed in Chrome 152.0.7977.65