Google · Google Chrome · CVE-2021-21172
**Name of the Vulnerable Software and Affected Versions**
Google Chrome versions prior to 89.0.4389.72
**Description**
The issue is related to insufficient policy enforcement in the File System API of Google Chrome, which can be exploited by a remote attacker to bypass filesystem restrictions. This can be achieved via a crafted HTML page, potentially impacting the confidentiality and integrity of protected information.
**Recommendations**
For versions prior to 89.0.4389.72, update to version 89.0.4389.72 or later to resolve the issue.
As a temporary workaround, consider restricting access to the File System API until a patch is available.