Impact
The flaw lies in Chrome’s handling of the file input element on Linux. A specially crafted HTML page can trigger erroneous behavior that may break out of the browser’s sandbox, allowing code to run with the user’s privileges. The weakness matches the categories of improper authorization and resource restriction, as reflected by CWE-269 and CWE-653. If exploited, an attacker could gain elevated privileges on the host system and access or modify local files and processes.
Affected Systems
Affected vendor is Google, product Chrome on Linux. All Linux builds of Chrome older than version 151.0.7922.72 contain the issue. Users running those releases are at risk until they upgrade to the fixed version or later.
Risk and Exploitability
The CVSS score of 7.1 indicates medium severity. The EPSS score is below 1%, implying a low current exploitation probability, and the vulnerability is not listed in the CISA KEV catalog. The likely attack path requires a remote attacker to serve a malicious HTML page that a Linux user opens in Chrome; the user’s action is inferred from the description and is not guaranteed to be mandatory for exploitation. Nonetheless, the potential for sandbox escape warrants prompt attention.
OpenCVE Enrichment
Debian DLA
Debian DSA