Description
UI misrepresentation in FileSystem in Google Chrome prior to 155.0.8059.39 allowed a remote attacker leveraging social engineering to bypass system access restrictions via a crafted HTML page. (Chromium security severity: Medium)
Published: 2026-10-06
Score: 5.4 Medium
EPSS: n/a
KEV: No
Impact: Unauthorized Access via FileSystem UI Misrepresentation
Action: Immediate Patch
AI Analysis

Impact

A flaw in the FileSystem interface of Google Chrome causes UI elements to be misrepresented, letting a maliciously crafted HTML page deceive a user into granting elevated file system permissions. The vulnerability can allow a remote attacker who succeeds in social engineering a victim to bypass the browser’s system access restrictions and read or write files beyond the intended sandbox. The weakness is identified as a presentation‑level flaw that does not involve code execution but grants unauthorized access to protected resources.

Affected Systems

Chromium‑based Google Chrome browsers running any revision earlier than 155.0.8059.39 are affected. No other vendors or product versions are listed as impacted.

Risk and Exploitability

The vulnerability is classified as medium severity, with no EPSS score available and not listed in the CISA KEV catalog. Exploitation requires a victim to visit a specially crafted web page; the attack vector is remote, relying on social engineering. Because the flaw is UI‑related rather than a traditional code‑execution bug, the direct risk is limited to unauthorized file access rather than full system compromise. Nonetheless, the potential impact justifies prompt remediation.

Generated by OpenCVE AI on October 6, 2026 at 21:25 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade to Google Chrome version 155.0.8059.39 or later to eliminate the misrepresentation bug.
  • Configure Chrome to auto‑update and verify that the latest version is installed on all endpoints.
  • Educate users to avoid interacting with unfamiliar or suspicious web pages, especially those that prompt file system access requests.

Generated by OpenCVE AI on October 6, 2026 at 21:25 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 06 Oct 2026 21:45:00 +0000

Type Values Removed Values Added
Title UI Misrepresentation in FileSystem Enabling Unauthorized Access

Tue, 06 Oct 2026 21:30:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 5.4, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:L'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 06 Oct 2026 19:00:00 +0000

Type Values Removed Values Added
Description UI misrepresentation in FileSystem in Google Chrome prior to 155.0.8059.39 allowed a remote attacker leveraging social engineering to bypass system access restrictions via a crafted HTML page. (Chromium security severity: Medium)
Weaknesses CWE-451
References

Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: Chrome

Published:

Updated: 2026-10-06T20:45:57.929Z

Reserved: 2026-10-06T16:32:16.749Z

Link: CVE-2026-106229

cve-icon Vulnrichment

Updated: 2026-10-06T20:43:29.948Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-10-06T19:17:49.680

Modified: 2026-10-06T21:17:07.393

Link: CVE-2026-106229

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-06T21:30:08Z

Weaknesses
  • CWE-451

    User Interface (UI) Misrepresentation of Critical Information