CVE-2026-84354
massIncorrect Authorization in Chrome FileSystem Allows Sandbox-Escaping RCE
Google Chrome versions prior to 152.0.7977.75 contain an incorrect authorization flaw (CWE-863) in the FileSystem component, meaning access checks on file system operations are not properly enforced. A remote attacker can trigger it by socially engineering a user into opening a crafted HTML page, which requires user interaction per the CVSS vector (UI:R). Successful exploitation yields arbitrary code execution outside the Chrome sandbox (scope changed), so attacker code is not contained by the browser's sandbox and can achieve high impact on confidentiality, integrity, and availability. All Chrome users running an affected version are exposed, with the Chromium project rating the issue High severity. Exploitation has not been observed: there is no known in-the-wild activity, no public proof of concept, the issue is absent from CISA KEV, and EPSS predicts only a 0.3% chance of exploitation in the next 30 days.
What to do: Update Chrome to 152.0.7977.75 or later on all desktop and mobile endpoints, and confirm the update has rolled out across your managed fleet rather than relying solely on auto-update timing. Until patched, caution users against opening untrusted HTML pages or links, since exploitation depends on social engineering and user interaction; enterprise administrators can also check fleet versions via endpoint management tooling.
| Google Chrome | prior to 152.0.7977.75 |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Incorrect authorization in FileSystem in Google Chrome prior to 152.0.7977.75 allowed a remote attacker leveraging social engineering to execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: High)
- Vendors
- Products
- chrome
- Weakness
- CWE-863
- Vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H
In the news0 stories
No ingested article mentions this CVE yet.