ZeroHour

CVE-2026-84354

mass

Incorrect Authorization in Chrome FileSystem Allows Sandbox-Escaping RCE

CVSS 3.1
9.6 critical
EPSS
<1%p19
Published
()
Modified
AI analysis

Google Chrome versions prior to 152.0.7977.75 contain an incorrect authorization flaw (CWE-863) in the FileSystem component, meaning access checks on file system operations are not properly enforced. A remote attacker can trigger it by socially engineering a user into opening a crafted HTML page, which requires user interaction per the CVSS vector (UI:R). Successful exploitation yields arbitrary code execution outside the Chrome sandbox (scope changed), so attacker code is not contained by the browser's sandbox and can achieve high impact on confidentiality, integrity, and availability. All Chrome users running an affected version are exposed, with the Chromium project rating the issue High severity. Exploitation has not been observed: there is no known in-the-wild activity, no public proof of concept, the issue is absent from CISA KEV, and EPSS predicts only a 0.3% chance of exploitation in the next 30 days.

What to do: Update Chrome to 152.0.7977.75 or later on all desktop and mobile endpoints, and confirm the update has rolled out across your managed fleet rather than relying solely on auto-update timing. Until patched, caution users against opening untrusted HTML pages or links, since exploitation depends on social engineering and user interaction; enterprise administrators can also check fleet versions via endpoint management tooling.

Affected
Google Chromeprior to 152.0.7977.75
Estimated exposure
mass≈3+ billion users (Chrome's global install base, all versions before 152.0.7977.75) — Chrome is the world's dominant desktop browser with billions of active installations, and every version prior to the 152.0.7977.75 fix is affected, so the realistic exposure spans essentially the entire Chrome user base.

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Incorrect authorization in FileSystem in Google Chrome prior to 152.0.7977.75 allowed a remote attacker leveraging social engineering to execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: High)

Vendors
google
Products
chrome
Weakness
CWE-863
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.