Description
Missing authorization in FileSystem in Google Chrome prior to 152.0.7977.75 allowed a remote attacker who had compromised the renderer process to bypass web origin policy via a crafted HTML page. (Chromium security severity: Medium)
Published: 2026-09-01
Score: n/a
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability resides in the lack of authorization checks within Google Chrome's FileSystem API. An attacker who has already obtained code execution in the renderer process can serve a crafted HTML page that bypasses the browser's same‑origin policy, allowing the attacker to read, write, or delete arbitrary files on the victim’s system. This breach can lead to data theft, tampering, or the delivery of malicious content, thereby impacting confidentiality, integrity, and availability.

Affected Systems

The impacted vendor is Google, specifically the Chrome browser. All releases prior to version 152.0.7977.75 are affected, including any derivative Chromium‑based browsers that have not installed the specified update.

Risk and Exploitability

Chromium assigns a medium severity to this issue. No EPSS score is provided and the vulnerability is not listed in CISA KEV, suggesting a moderate probability of exploitation. However, the flaw requires that an attacker already obtain code execution within the renderer process – a prerequisite that may reduce the overall risk. Nonetheless, this condition still means that organizations using vulnerable Chrome versions should treat the issue with urgency and remediate promptly.

Generated by OpenCVE AI on September 2, 2026 at 04:03 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Update Chrome to version 152.0.7977.75 or newer
  • Apply the same update to all derivative Chromium browsers that use the affected components
  • If an immediate update is not possible, configure Chrome to disable the FileSystem API via enterprise policy or by using an extension that blocks the API

Generated by OpenCVE AI on September 2, 2026 at 04:03 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 02 Sep 2026 04:30:00 +0000

Type Values Removed Values Added
Title Remote Origin Policy Bypass via FileSystem API in Chrome

Wed, 02 Sep 2026 02:45:00 +0000

Type Values Removed Values Added
First Time appeared Google
Google chrome
Vendors & Products Google
Google chrome

Wed, 02 Sep 2026 00:00:00 +0000

Type Values Removed Values Added
Description Missing authorization in FileSystem in Google Chrome prior to 152.0.7977.75 allowed a remote attacker who had compromised the renderer process to bypass web origin policy via a crafted HTML page. (Chromium security severity: Medium)
Weaknesses CWE-862
References

cve-icon MITRE

Status: PUBLISHED

Assigner: Chrome

Published:

Updated: 2026-09-01T23:42:27.804Z

Reserved: 2026-09-01T16:20:18.901Z

Link: CVE-2026-84328

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-02T00:18:27.657

Modified: 2026-09-02T00:18:27.657

Link: CVE-2026-84328

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-02T04:15:05Z

Weaknesses