CVE-2026-103626: Incorrect authorization in FileSystem
Incorrect authorization in FileSystem in Google Chrome on on Windows prior to 154.0.8037.97 allowed a remote attacker leveraging social engineering to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: High)
Credit
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 154.0.8037.97
Event History
Peer vulnerabilities
Found alongside the following vulnerabilities.
Frequently Asked Questions
Which systems are affected?
The issue affects Google Chrome on Windows before version 154.0.8037.97. The provided information does not identify impact on other operating systems.
What does an attacker need to exploit this?
An attacker must use social engineering to get a user to interact with a crafted HTML page. Successful exploitation could allow arbitrary code execution outside Chrome's sandbox.
What should teams do if they cannot patch immediately?
The provided information identifies social engineering and a crafted HTML page as the delivery path. Until Chrome can be updated, reduce exposure to untrusted web content and warn users about unsolicited or suspicious links and pages.