Description
Incorrect authorization in FileSystem in Google Chrome prior to 152.0.7977.65 allowed a remote attacker leveraging social engineering to bypass system access restrictions via a crafted HTML page. (Chromium security severity: Medium)
Published: 2026-08-25
Score: 5.4 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Unauthorized file system access via crafted page
Action: Apply Patch
AI Analysis

Impact

The flaw is an incorrect authorization check within Chrome’s FileSystem API. It allows a remote attacker to deceive a user with a malicious HTML page and gain privileges to traverse or read the user’s file system, removing the intended sandboxing that confines the browser to the user’s profile directories and exposing sensitive local files.

Affected Systems

All releases of Google Chrome older than 152.0.7977.65 are vulnerable. Any user running those browsers on the desktop is susceptible when visiting a crafted web page.

Risk and Exploitability

The Chromium security severity is Medium and the CVSS score of 5.4 reflects a moderate risk. The EPSS score of < 1% indicates a low exploitation probability. The vulnerability is not listed in the CISA KEV catalogue. Exploitation requires social engineering; the victim must open a malicious page. While the attack surface is limited to users who load such content, the potential impact of unauthorized file access is significant. Prompt patching reduces the attack window and limits exploitation likelihood.

Generated by OpenCVE AI on August 31, 2026 at 19:29 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade to Chrome 152.0.7977.65 or newer
  • Disable or restrict the FileSystem API using enterprise policy or a browser extension
  • Educate users to avoid opening untrusted HTML pages or content from suspicious sites

Generated by OpenCVE AI on August 31, 2026 at 19:29 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Debian DLA Debian DLA DLA-4771-1 chromium security update
Debian DSA Debian DSA DSA-6482-1 chromium security update
History

Mon, 31 Aug 2026 19:45:00 +0000

Type Values Removed Values Added
Title Incorrect Authorization in Chrome FileSystem API Allows Unauthorized File Access

Mon, 31 Aug 2026 17:30:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}

cvssV3_1

{'score': 5.4, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N'}


Mon, 31 Aug 2026 17:15:00 +0000

Type Values Removed Values Added
Title Incorrect Authorization in Chrome FileSystem Leading to Remote Access via Crafted Page

Mon, 31 Aug 2026 15:15:00 +0000

Type Values Removed Values Added
CPEs cpe:2.3:a:google:chrome:*:*:*:*:*:*:*:*
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N'}


Wed, 26 Aug 2026 03:45:00 +0000

Type Values Removed Values Added
First Time appeared Google
Google chrome
Vendors & Products Google
Google chrome

Wed, 26 Aug 2026 02:45:00 +0000

Type Values Removed Values Added
Title Incorrect Authorization in Chrome FileSystem Leading to Remote Access via Crafted Page

Tue, 25 Aug 2026 20:30:00 +0000

Type Values Removed Values Added
Description Incorrect authorization in FileSystem in Google Chrome prior to 152.0.7977.65 allowed a remote attacker leveraging social engineering to bypass system access restrictions via a crafted HTML page. (Chromium security severity: Medium)
Weaknesses CWE-863
References

cve-icon MITRE

Status: PUBLISHED

Assigner: Chrome

Published:

Updated: 2026-08-31T16:04:27.600Z

Reserved: 2026-08-25T06:08:58.686Z

Link: CVE-2026-79088

cve-icon Vulnrichment

Updated: 2026-08-31T16:04:24.055Z

cve-icon NVD

Status : Modified

Published: 2026-08-25T21:18:04.430

Modified: 2026-08-31T16:19:14.320

Link: CVE-2026-79088

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-31T19:30:05Z

Weaknesses