Impact
The flaw is an incorrect authorization check within Chrome’s FileSystem API. It allows a remote attacker to deceive a user with a malicious HTML page and gain privileges to traverse or read the user’s file system, removing the intended sandboxing that confines the browser to the user’s profile directories and exposing sensitive local files.
Affected Systems
All releases of Google Chrome older than 152.0.7977.65 are vulnerable. Any user running those browsers on the desktop is susceptible when visiting a crafted web page.
Risk and Exploitability
The Chromium security severity is Medium and the CVSS score of 5.4 reflects a moderate risk. The EPSS score of < 1% indicates a low exploitation probability. The vulnerability is not listed in the CISA KEV catalogue. Exploitation requires social engineering; the victim must open a malicious page. While the attack surface is limited to users who load such content, the potential impact of unauthorized file access is significant. Prompt patching reduces the attack window and limits exploitation likelihood.
OpenCVE Enrichment
Debian DLA
Debian DSA