
Zip Slip leading to Arbitrary File Write and Privilege Escalation in Google Web Designer CVE: CVE-2026-3223 Vendor: Google Product: Web Designer CVSS: 8.4 Credits: n/a Description: Arbitrary file write & potential privilege escalation exploiting zip slip vulnerability in Google Web Designer. References: • https://dbugs.ptsecurity.com/vulnerability/CVE-2026-3223 • https://bughunters.google.com/reports/vrp/FJMQGy8oo
Post summary
A new CVE-2026-3223 zip slip vulnerability in Google Web Designer allows arbitrary file write and potential privilege escalation, with a CVSS score of 8.4, but no PoC, exploit, or patch details are provided.




