Description
Incorrect authorization in FileSystem in Google Chrome prior to 152.0.7977.65 allowed a remote attacker leveraging social engineering to bypass system access restrictions via a crafted HTML page. (Chromium security severity: Medium)
Published: 2026-08-25
Score: 4.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Authorization bypass allowing potential remote file access
Action: Immediate Patch
AI Analysis

Impact

The vulnerability lies in the Chrome FileSystem API where incorrect authorization checks permit a crafted HTML page to access restricted system files. This flaw enables a remote attacker, through a social engineering vector, to bypass normal operating system access controls without compromising the browser’s internal security boundary. The flaw is categorized as a CWE‑863 unauthorized access. Based on the description, it is inferred that exploitation could allow an attacker to read or modify files that should remain protected, potentially exposing sensitive data or enabling further exploitation of the target system.

Affected Systems

Google Chrome is affected in all builds prior to version 152.0.7977.65. Any user running an earlier release, regardless of operating system, is potentially vulnerable until they upgrade.

Risk and Exploitability

Chromium rates the threat as medium severity with a CVSS score of 4.3. The EPSS score for this vulnerability is < 1%, indicating a very low probability of exploitation, and the vulnerability is not listed in the CISA KEV catalogue. The attack requires user interaction with a malicious web page, so the primary vector is social engineering. It is inferred that no public exploits have been reported, so the risk remains moderate and the flaw should be mitigated promptly.

Generated by OpenCVE AI on August 29, 2026 at 00:36 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Update Chrome to the latest stable release (≥ 152.0.7977.65).
  • If an upgrade is temporarily unavailable, disable the FileSystem API via Chrome policies or flags, such as setting "AllowFileSystem" to false.
  • Educate users to avoid opening unknown HTML pages or links that may lead to malicious content.

Generated by OpenCVE AI on August 29, 2026 at 00:36 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Debian DLA Debian DLA DLA-4771-1 chromium security update
Debian DSA Debian DSA DSA-6482-1 chromium security update
History

Mon, 31 Aug 2026 17:00:00 +0000

Type Values Removed Values Added
CPEs cpe:2.3:a:google:chrome:*:*:*:*:*:*:*:*

Sat, 29 Aug 2026 01:00:00 +0000

Type Values Removed Values Added
Title Chrome FileSystem API Authorization Bypass via Crafted HTML Page

Fri, 28 Aug 2026 20:30:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 4.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N'}


Wed, 26 Aug 2026 03:15:00 +0000

Type Values Removed Values Added
First Time appeared Google
Google chrome
Vendors & Products Google
Google chrome

Wed, 26 Aug 2026 01:15:00 +0000

Type Values Removed Values Added
Title Chrome FileSystem API Authorization Bypass via Crafted HTML Page

Tue, 25 Aug 2026 20:30:00 +0000

Type Values Removed Values Added
Description Incorrect authorization in FileSystem in Google Chrome prior to 152.0.7977.65 allowed a remote attacker leveraging social engineering to bypass system access restrictions via a crafted HTML page. (Chromium security severity: Medium)
Weaknesses CWE-863
References

cve-icon MITRE

Status: PUBLISHED

Assigner: Chrome

Published:

Updated: 2026-08-28T18:46:00.580Z

Reserved: 2026-08-25T06:10:23.106Z

Link: CVE-2026-79143

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Analyzed

Published: 2026-08-25T21:18:09.607

Modified: 2026-08-31T16:53:12.123

Link: CVE-2026-79143

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-29T00:45:04Z

Weaknesses