Junglewise Threat Intelligence

CVE-2026-79276: Google Chrome improper privilege management in FileSystem

CVE-2026-79276 · Severity: medium · CVSS 4.3 · Published 2026-08-25

Technologies: Google Chrome. Vendors: Google.

Executive brief

Google Chrome is a web browser used by billions of users worldwide to browse the internet. This vulnerability allows a remote attacker to bypass system access restrictions through a specially crafted webpage, potentially gaining unauthorized access to files or sensitive system resources. An attacker would need to trick a user into visiting a malicious website to exploit this issue.

Technical details

This vulnerability involves improper privilege management in the FileSystem component of Google Chrome prior to version 152.0.7977.65. The flaw allows a remote attacker to bypass system access restrictions via a crafted HTML page, leveraging social engineering (user interaction required). The attack vector is network-based and does not require authentication. An attacker can craft a malicious HTML page that, when visited by a user, exploits the privilege management weakness to gain unauthorized access to filesystem operations. The vulnerability was patched in Chrome 152.0.7977.65 released on August 25, 2026.

Affected products

  • Google Chrome prior to 152.0.7977.65

Timeline

  • 2026-08-25: disclosed: CVE-2026-79276 disclosed; Chrome 152.0.7977.65 released with fix
  • 2026-08-25: patched: Fixed in Chrome 152.0.7977.65

References

Related threats