Impact
Google Chrome on Windows contains an incorrect authorization mechanism for the FileSystem API in versions prior to 154.0.8037.97. A remote attacker can use social engineering to get a user to load a crafted HTML page that triggers arbitrary code execution outside of the browser sandbox. This flaw falls under CWE‑863 and can compromise system confidentiality, integrity, and availability by giving the attacker full control over the affected machine.
Affected Systems
Google Chrome running on Windows platforms, any installation of Chrome with a version earlier than 154.0.8037.97 is vulnerable.
Risk and Exploitability
The vulnerability can be exploited only when a user accesses a malicious page, implying that social engineering is required. There is no public EPSS or KEV data, but the Chromium severity is reported as High, indicating a significant potential impact. Because exploitation relies on user interaction, the likelihood of remote exploitation is moderate, yet the consequences if successful are severe, warranting prompt mitigation.
OpenCVE Enrichment