Missing Authorization Flaw in Google Chrome Affects Multiple Versions
CVE-2026-84328

Currently unrated

Key Information:

Vendor

Google

Status
Vendor
CVE Published:
1 September 2026

What is CVE-2026-84328?

A vulnerability exists in Google Chrome versions prior to 152.0.7977.75, where a missing authorization in the FileSystem component enables remote attackers to bypass web origin policies. By crafting a malicious HTML page, an attacker who has compromised the renderer process can exploit this weakness to gain unauthorized access to resources, potentially leading to significant security breaches. This flaw underscores the importance of strict authorization checks within web applications.

Affected Version(s)

Chrome 152.0.7977.75

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.