Incorrect Authorization in Google Chrome FileSystem Leading to Remote Code Execution
CVE-2026-84354

Currently unrated

Key Information:

Vendor

Google

Status
Vendor
CVE Published:
1 September 2026

What is CVE-2026-84354?

An incorrect authorization vulnerability in the FileSystem component of Google Chrome prior to version 152.0.7977.75 could be exploited by remote attackers. By utilizing social engineering techniques, an attacker could craft a specially designed HTML page that allows the execution of arbitrary code outside the confines of the browser's sandbox, compromising user security.

Affected Version(s)

Chrome 152.0.7977.75

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.