Executive brief
Google Chrome's FileSystem API lacked proper authorization checks in versions before 153.0.8010.36. An attacker could trick users into visiting a malicious webpage that exploits this flaw to access restricted system files. This allows unauthorized access to sensitive data stored locally on the user's computer.
Technical details
A missing authorization vulnerability exists in the FileSystem API implementation of Google Chrome prior to version 153.0.8010.36. The vulnerability allows an attacker to bypass system access restrictions through a crafted HTML page, requiring social engineering to trick the user into visiting the malicious site. The attack is delivered over the network and does not require prior authentication. An attacker can gain unauthorized access to files on the affected system. The vulnerability is fixed in Chrome 153.0.8010.36 and later releases.
Affected products
- Google Chrome prior to 153.0.8010.36
Timeline
- 2026-09-09: disclosed: CVE-2026-87493 disclosed
- 2026-09-08: patched: Fixed in Chrome 153.0.8010.36