Description
Missing authorization in FileSystem in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to bypass system access restrictions via a crafted HTML page. (Chromium security severity: Medium)
Published: 2026-09-09
Score: 6.5 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Unauthorized File System Access
Action: Patch Now
AI Analysis

Impact

This vulnerability arises from missing authorization checks in Google Chrome's FileSystem API. A crafted HTML page can trick the browser into granting file system access that should be restricted, allowing the attacker to read or modify arbitrary files on the host. The weakness is a missing authorization flaw (CWE‑862) and results in unauthorized file system access outside the browser sandbox.

Affected Systems

Affected systems are Google Chrome browsers older than version 153.0.8010.36. Any Windows, macOS, or Linux desktop installation running an unpatched browser can be impacted. The advisory lists only the Chrome product; no other vendor variants are noted.

Risk and Exploitability

The vulnerability has a CVSS score of 6.5, indicating medium severity within Chromium's own scoring and it is not listed in CISA KEV. The EPSS score is below 1 %, suggesting that the likelihood of widespread exploitation is low. Because the attack requires a crafted local HTML page served from an untrusted source, it is unlikely to be widely exploited without prior user interaction. Deploying the updated browser mitigates the risk entirely, and no public exploits are known.

Generated by OpenCVE AI on September 11, 2026 at 00:00 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Update Google Chrome to version 153.0.8010.36 or later.
  • Ensure that automatic updates are enabled so that future patches are received promptly.
  • If an update cannot be applied immediately, consider temporarily disabling or restricting the FileSystem API for untrusted sites using enterprise policy settings.

Generated by OpenCVE AI on September 11, 2026 at 00:00 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Debian DLA Debian DLA DLA-4790-1 chromium security update
Debian DSA Debian DSA DSA-6506-1 chromium security update
History

Fri, 11 Sep 2026 14:15:00 +0000

Type Values Removed Values Added
CPEs cpe:2.3:a:google:chrome:*:*:*:*:*:*:*:*

Fri, 11 Sep 2026 00:45:00 +0000

Type Values Removed Values Added
First Time appeared Google
Google chrome
Vendors & Products Google
Google chrome

Fri, 11 Sep 2026 00:30:00 +0000

Type Values Removed Values Added
Title Remote File System Access Bypass in Chrome via Crafted HTML Page

Thu, 10 Sep 2026 19:30:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 09 Sep 2026 07:30:00 +0000

Type Values Removed Values Added
Title Remote File System Access Bypass in Chrome via Crafted HTML Page

Wed, 09 Sep 2026 01:00:00 +0000

Type Values Removed Values Added
Description Missing authorization in FileSystem in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to bypass system access restrictions via a crafted HTML page. (Chromium security severity: Medium)
Weaknesses CWE-862
References

cve-icon MITRE

Status: PUBLISHED

Assigner: Chrome

Published:

Updated: 2026-09-10T18:39:01.098Z

Reserved: 2026-09-08T22:42:14.110Z

Link: CVE-2026-87603

cve-icon Vulnrichment

Updated: 2026-09-10T18:37:39.247Z

cve-icon NVD

Status : Analyzed

Published: 2026-09-09T01:17:18.340

Modified: 2026-09-11T13:57:56.590

Link: CVE-2026-87603

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-11T00:30:14Z

Weaknesses