Impact
Google Chrome prior to 152.0.7977.65 incorrectly applied case‑sensitive file name handling within its FileSystem API. A crafted HTML page can trick a user into loading the page; the API then treats file paths in a case‑insensitive manner, allowing the attacker to read or modify files that should normally be protected. This flaw effectively elevates the attacker’s privileges on the victim’s machine by bypassing expected system access controls.
Affected Systems
The flaw is confined to the desktop version of Google Chrome before 152.0.7977.65. No other Google products or extensions are explicitly listed as affected.
Risk and Exploitability
Chromium labels the issue as medium severity; CVSS score is 6.5, EPSS score is < 1%, and it is not listed in the CISA KEV catalog. The attack requires a malicious HTML page that the victim opens in Chrome, so it is a remote, social‑engineering‑based vector. Successful exploitation would grant the attacker arbitrary local file access, representing a moderate risk given the low exploit probability.
OpenCVE Enrichment
Debian DLA
Debian DSA