← Back to overview

CVE-2026-84354 describes an incorrect authorization vulnerability in the FileSystem component of Google Chrome prior to version 152.0.7977.75. A remote attacker can leverage social engineering techniques to exploit this flaw via a crafted HTML page. Successful exploitation allows arbitrary code execution outside the Chrome sandbox, effectively bypassing a key security boundary. The vulnerability is rated High severity by the Chromium security team. The fix was included in the stable channel update for desktop released in September 2026. Users are advised to update to Chrome 152.0.7977.75 or later to mitigate the risk. The attack vector requires user interaction through social engineering, making it a realistic threat in targeted or phishing-style campaigns.

Affected products

  • Google Chrome

Related CVE's

  • CVE-2026-84354

Categories

  • Web Technologies
  • Zero-Day Vulnerabilities