Description
Incorrect authorization in FileSystem in Google Chrome on on Windows prior to 154.0.8037.97 allowed a remote attacker leveraging social engineering to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: High)
Published: 2026-10-02
Score: n/a
EPSS: n/a
KEV: No
Impact: Remote Code Execution via FileSystem Authorization Bypass
Action: Immediate Patch
AI Analysis

Impact

Google Chrome on Windows contains an incorrect authorization mechanism for the FileSystem API in versions prior to 154.0.8037.97. A remote attacker can use social engineering to get a user to load a crafted HTML page that triggers arbitrary code execution outside of the browser sandbox. This flaw falls under CWE‑863 and can compromise system confidentiality, integrity, and availability by giving the attacker full control over the affected machine.

Affected Systems

Google Chrome running on Windows platforms, any installation of Chrome with a version earlier than 154.0.8037.97 is vulnerable.

Risk and Exploitability

The vulnerability can be exploited only when a user accesses a malicious page, implying that social engineering is required. There is no public EPSS or KEV data, but the Chromium severity is reported as High, indicating a significant potential impact. Because exploitation relies on user interaction, the likelihood of remote exploitation is moderate, yet the consequences if successful are severe, warranting prompt mitigation.

Generated by OpenCVE AI on October 2, 2026 at 17:27 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade Google Chrome to version 154.0.8037.97 or later to apply the fixed authorization checks.
  • Verify that the browser’s auto‑update feature is enabled so that future security releases are installed automatically.
  • If an upgrade cannot be performed immediately, temporarily disable or restrict access to the affected FileSystem API through Chrome’s settings or group‑policy restrictions to mitigate the risk while awaiting a patch.

Generated by OpenCVE AI on October 2, 2026 at 17:27 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 02 Oct 2026 17:45:00 +0000

Type Values Removed Values Added
Title Unauthorized FileSystem Access Leading to Remote Code Execution in Chrome on Windows
First Time appeared Google
Google chrome
Vendors & Products Google
Google chrome

Fri, 02 Oct 2026 16:15:00 +0000

Type Values Removed Values Added
Description Incorrect authorization in FileSystem in Google Chrome on on Windows prior to 154.0.8037.97 allowed a remote attacker leveraging social engineering to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: High)
Weaknesses CWE-863
References

cve-icon MITRE

Status: PUBLISHED

Assigner: Chrome

Published:

Updated: 2026-10-02T16:07:54.337Z

Reserved: 2026-09-30T23:12:18.647Z

Link: CVE-2026-103626

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-10-02T16:16:43.717

Modified: 2026-10-02T17:47:56.067

Link: CVE-2026-103626

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-02T17:30:18Z

Weaknesses