Impact
The vulnerability arises from incorrect reference resolution in the FileSystem component of Google Chrome. An attacker who tricks a user into loading a crafted HTML page can potentially cause code to execute outside the browser sandbox. This flaw allows the attacker to gain privileges beyond the normal security boundaries of the web browser, exposing the host system to arbitrary code execution.
Affected Systems
Google Chrome browsers running any Windows, macOS, or Linux desktop build prior to version 152.0.7977.65 are affected. The issue was identified in the stable channel and applies only to desktop installations of Chrome.
Risk and Exploitability
According to the CVE description, Chromium rates the issue as medium security severity, even though the CVSS score of 9.6 indicates strong technical impact. Because the EPSS score is < 1% and the vulnerability is not listed in the CISA KEV catalog, the likelihood of widespread exploitation remains uncertain. However, the attack vector is remote via social engineering and a crafted HTML page, making it feasible for an attacker to target a user without additional network access.
OpenCVE Enrichment
Debian DLA
Debian DSA