Sceawere

Vulnerability Detail

CVE-2026-84323UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

Google Chrome FileSystem Authorization Bypass

Vulnerability Metadata

Severity
Medium
Score / CVSS
5.3
Creation Date
1d ago
Vendor
Google
Product
Chrome
Attack Type
Missing authorization
Vector String
CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:N/A:N
Attack Complexity
HIGH

Narrative and Response

Description

Missing authorization in FileSystem in Google Chrome prior to 152.0.7977.75 allowed a remote attacker who had compromised the renderer process and leveraged social engineering to obtain sensitive information via a crafted HTML page. (Chromium security severity: Medium)

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "5.3",
  "pubDate": "2026-09-02T00:18:27.113Z",
  "pubdate": "2026-09-02T00:18:27.113Z",
  "executiveSummary": "A vulnerability categorized as a missing authorization flaw exists within the FileSystem component of Google Chrome, affecting versions prior to 152.0.7977.75.\nThis flaw allows a remote attacker to bypass intended security controls to gain unauthorized access to sensitive information.\nThe vulnerability requires a multi-stage attack vector, necessitating both a successful compromise of the browser's renderer process and the execution of social engineering tactics against the end user.\nThe impact of a successful exploit is the unauthorized disclosure of sensitive data, compromising user privacy and potentially exposing local file system structures.\nAssessed as having a Medium severity, the vulnerability highlights a weakness in the trust boundaries governing file system interactions when the rendering engine is operating under compromised conditions.\nDefense strategies must focus on prompt version updates and user-centric security awareness to mitigate the prerequisite social engineering component.",
  "technicalDetails": "The vulnerability stems from an improper authorization implementation within the FileSystem API handling logic in Google Chrome. Specifically, the FileSystem subsystem fails to sufficiently validate authorization tokens or context-bound permissions when requests originate from the renderer process.\nThe root cause is a deficiency in the internal security checks that ensure the renderer process—which is intended to operate within a strictly isolated sandbox—cannot perform unauthorized FileSystem operations without explicit user mediation or appropriate privilege elevation.\nThe exploitation flow begins with an attacker achieving arbitrary code execution within the browser's renderer process. This is typically achieved via a separate vulnerability, such as a memory corruption bug or an exploit in a web-exposed API. Once the renderer is compromised, the attacker resides within the sandboxed environment but is restricted by the browser's security architecture.\nTo transition from a compromised renderer to unauthorized file system access, the attacker must employ social engineering tactics. These tactics are designed to deceive the user into interacting with a crafted HTML page in a manner that bypasses or satisfies existing security prompts or authorization checks. By leveraging this user interaction, the attacker tricks the application into granting access to sensitive file system regions that should otherwise be restricted based on the current security context.\nOnce the authorization check is bypassed, the attacker can interact with the FileSystem component to read, and potentially manipulate, data that the browser has access to. The payload behavior is contingent upon the attacker's ability to navigate the local environment to target specific file structures or browser-stored data assets.\nThe vulnerability affects all Google Chrome versions prior to 152.0.7977.75. Since the flaw involves a bypass of authorization mechanisms, it does not strictly require high-privilege system access on the host operating system, but rather relies on the logic error within the browser's internal permission management framework to escalate the capabilities of the already compromised renderer process.\nPost-exploitation, the impact is primarily centered on data exfiltration. Because the renderer process acts as the intermediary, the attacker can effectively tunnel sensitive local information through the malicious HTML page, sending the data back to an attacker-controlled remote server."
}
CVE-2026-84323: Google Chrome FileSystem Authorization Bypass (MEDIUM Severity, CVSS: 5.3) - Sceawere