Junglewise Threat Intelligence

CVE-2026-84354: Google Chrome incorrect authorization in FileSystem

CVE-2026-84354 · Severity: critical · CVSS 9.6 · Published 2026-09-02

Technologies: Google Chrome. Vendors: Google.

Executive brief

Google Chrome contains an authorization flaw in its FileSystem functionality that allows attackers to bypass the browser sandbox and execute arbitrary code on a user's computer. An attacker can exploit this by crafting a malicious webpage and tricking a user into visiting it, potentially giving the attacker full control over the victim's system and access to all files and data stored on the device.

Technical details

The vulnerability is an incorrect authorization issue in Chrome's FileSystem implementation that permits a remote attacker to escape the sandbox restriction and execute arbitrary code with system privileges. The attack requires social engineering to deliver a crafted HTML page to the victim, but no additional authentication or user interaction beyond visiting the malicious page is needed. An attacker exploiting this flaw can gain complete code execution outside the security sandbox, allowing access to sensitive files, system resources, and potential lateral movement within the system. The vulnerability affects Chrome versions prior to 152.0.7977.75 and has been patched in that version and later.

Affected products

  • Google Chrome prior to 152.0.7977.75

Timeline

  • 2026-09-02: disclosed
  • 2026-09-02: patched: Fixed in Chrome 152.0.7977.75

References

Related threats