Executive brief
Google Chrome is a web browser used by billions of users worldwide to browse the internet. This vulnerability allows a remote attacker to bypass system access restrictions through a specially crafted webpage, potentially gaining unauthorized access to files or sensitive system resources. An attacker would need to trick a user into visiting a malicious website to exploit this issue.
Technical details
This vulnerability involves improper privilege management in the FileSystem component of Google Chrome prior to version 152.0.7977.65. The flaw allows a remote attacker to bypass system access restrictions via a crafted HTML page, leveraging social engineering (user interaction required). The attack vector is network-based and does not require authentication. An attacker can craft a malicious HTML page that, when visited by a user, exploits the privilege management weakness to gain unauthorized access to filesystem operations. The vulnerability was patched in Chrome 152.0.7977.65 released on August 25, 2026.
Affected products
- Google Chrome prior to 152.0.7977.65
Timeline
- 2026-08-25: disclosed: CVE-2026-79276 disclosed; Chrome 152.0.7977.65 released with fix
- 2026-08-25: patched: Fixed in Chrome 152.0.7977.65