Impact
A flaw in the FileSystem interface of Google Chrome causes UI elements to be misrepresented, letting a maliciously crafted HTML page deceive a user into granting elevated file system permissions. The vulnerability can allow a remote attacker who succeeds in social engineering a victim to bypass the browser’s system access restrictions and read or write files beyond the intended sandbox. The weakness is identified as a presentation‑level flaw that does not involve code execution but grants unauthorized access to protected resources.
Affected Systems
Chromium‑based Google Chrome browsers running any revision earlier than 155.0.8059.39 are affected. No other vendors or product versions are listed as impacted.
Risk and Exploitability
The vulnerability is classified as medium severity, with no EPSS score available and not listed in the CISA KEV catalog. Exploitation requires a victim to visit a specially crafted web page; the attack vector is remote, relying on social engineering. Because the flaw is UI‑related rather than a traditional code‑execution bug, the direct risk is limited to unauthorized file access rather than full system compromise. Nonetheless, the potential impact justifies prompt remediation.
OpenCVE Enrichment