Description
Incorrect reference resolution in FileSystem in Google Chrome prior to 152.0.7977.65 allowed a remote attacker leveraging social engineering to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Medium)
Published: 2026-08-25
Score: 9.6 Critical
EPSS: < 1% Very Low
KEV: No
Impact: Remote Code Execution
Action: Immediate Patch
AI Analysis

Impact

The vulnerability arises from incorrect reference resolution in the FileSystem component of Google Chrome. An attacker who tricks a user into loading a crafted HTML page can potentially cause code to execute outside the browser sandbox. This flaw allows the attacker to gain privileges beyond the normal security boundaries of the web browser, exposing the host system to arbitrary code execution.

Affected Systems

Google Chrome browsers running any Windows, macOS, or Linux desktop build prior to version 152.0.7977.65 are affected. The issue was identified in the stable channel and applies only to desktop installations of Chrome.

Risk and Exploitability

According to the CVE description, Chromium rates the issue as medium security severity, even though the CVSS score of 9.6 indicates strong technical impact. Because the EPSS score is < 1% and the vulnerability is not listed in the CISA KEV catalog, the likelihood of widespread exploitation remains uncertain. However, the attack vector is remote via social engineering and a crafted HTML page, making it feasible for an attacker to target a user without additional network access.

Generated by OpenCVE AI on August 26, 2026 at 20:24 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Update Google Chrome to version 152.0.7977.65 or later; this release contains a patch that corrects the reference resolution logic.
  • Ensure automatic updates are enabled so future patches are applied promptly.
  • Consider disabling or restricting the uses of the FileSystem API in untrusted web content if immediate updating is not possible.

Generated by OpenCVE AI on August 26, 2026 at 20:24 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Debian DLA Debian DLA DLA-4771-1 chromium security update
Debian DSA Debian DSA DSA-6482-1 chromium security update
History

Thu, 27 Aug 2026 17:45:00 +0000

Type Values Removed Values Added
CPEs cpe:2.3:a:google:chrome:*:*:*:*:*:*:*:*

Thu, 27 Aug 2026 05:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Wed, 26 Aug 2026 20:45:00 +0000

Type Values Removed Values Added
Title Incorrect FileSystem Reference Resolution Allows Remote Code Execution in Google Chrome

Wed, 26 Aug 2026 17:30:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 9.6, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H'}


Tue, 25 Aug 2026 23:45:00 +0000

Type Values Removed Values Added
Title Incorrect FileSystem Reference Resolution Allows Remote Code Execution in Google Chrome

Tue, 25 Aug 2026 23:00:00 +0000

Type Values Removed Values Added
First Time appeared Google
Google chrome
Vendors & Products Google
Google chrome

Tue, 25 Aug 2026 20:30:00 +0000

Type Values Removed Values Added
Description Incorrect reference resolution in FileSystem in Google Chrome prior to 152.0.7977.65 allowed a remote attacker leveraging social engineering to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Medium)
Weaknesses CWE-706
References

cve-icon MITRE

Status: PUBLISHED

Assigner: Chrome

Published:

Updated: 2026-08-27T03:58:20.668Z

Reserved: 2026-08-25T06:06:46.158Z

Link: CVE-2026-78985

cve-icon Vulnrichment

Updated: 2026-08-26T16:52:00.329Z

cve-icon NVD

Status : Analyzed

Published: 2026-08-25T21:17:54.863

Modified: 2026-08-27T17:25:49.520

Link: CVE-2026-78985

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-26T20:30:11Z

Weaknesses
  • CWE-706

    Use of Incorrectly-Resolved Name or Reference