Impact
Insufficient policy enforcement in Chrome's FileSystem API allows a remote attacker to bypass the browser's discretionary access control by loading a specially crafted HTML page. The flaw permits the attacker to read or write files that are not explicitly granted by the user, potentially leading to data leakage or modification. The weakness is an improper access control issue (CWE-284).
Affected Systems
Google Chrome installations running a version earlier than 150.0.7871.47 are affected. That includes all desktop builds before the June 2026 stable channel update. The vulnerability is present in every Chrome build prior to the patched release.
Risk and Exploitability
The CVSS score is 4.3, and the EPSS score is < 1%, indicating a low probability of exploitation. The flaw is not listed in the CISA KEV catalog. The Chromium severity is low. Based on the description, the likely attack vector is a crafted the attacker must get a user to open the malicious page. If successful, the attacker can read or modify files that normally fall under Chrome's sandbox protections.
OpenCVE Enrichment
Debian DLA
Debian DSA