CVE-2026-79088: Medium Incorrect authorization in FileSystem
Chromium: CVE-2026-79088 Incorrect authorization in FileSystem
Other sources
Incorrect authorization in FileSystem in Google Chrome prior to 152.0.7977.65 allowed a remote attacker leveraging social engineering to bypass system access restrictions via a crafted HTML page. (Chromium security severity: Medium)
— MITRE
This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see Google Chrome Releases for more information.
— Microsoft
Credit
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 152.0.4191.53 - Upgrade
Upgrade
Google Chrometo a version that resolves this vulnerability.Fixed in 152.0.7977.65
Event History
Peer vulnerabilities
Found alongside the following vulnerabilities.
Frequently Asked Questions
What does an attacker need to exploit this issue?
The attacker needs to persuade a user to interact with a crafted HTML page. The issue is remotely exploitable through that social-engineering scenario.
Which Chrome versions should be updated?
Google Chrome versions prior to 152.0.7977.65 are affected. Update Chrome to 152.0.7977.65 or a later version.