Impact
In Google Chrome versions prior to 149.0.7827.53 an inappropriate implementation of File System Access handling allows a remote attacker who lures a user into performing specific UI gestures on a crafted web page to bypass discretionary access controls, effectively obtaining elevated file system permissions beyond those normally granted to the user. The flaw is associated with CWE-284 and CWE-551.
Affected Systems
The vulnerability affects any platform where an unpatched Google Chrome installation is running. Users of Chrome before updating to 149.0.7827.53 are at risk; no other vendors or products are directly impacted.
Risk and Exploitability
The attacker must first persuade the victim to interact with the malicious page, so the attack vector is user-dependent and somewhat limited in scale. The EPSS score is below 1% and the CVSS score of 6.5 indicates moderate severity. The flaw is not currently listed in CISA’s KEV catalog. Nonetheless, because it can lead to privilege escalation, it warrants prompt patching by all affected users.
OpenCVE Enrichment
Debian DSA