Impact
The vulnerability lies in the Chrome FileSystem API where incorrect authorization checks permit a crafted HTML page to access restricted system files. This flaw enables a remote attacker, through a social engineering vector, to bypass normal operating system access controls without compromising the browser’s internal security boundary. The flaw is categorized as a CWE‑863 unauthorized access. Based on the description, it is inferred that exploitation could allow an attacker to read or modify files that should remain protected, potentially exposing sensitive data or enabling further exploitation of the target system.
Affected Systems
Google Chrome is affected in all builds prior to version 152.0.7977.65. Any user running an earlier release, regardless of operating system, is potentially vulnerable until they upgrade.
Risk and Exploitability
Chromium rates the threat as medium severity with a CVSS score of 4.3. The EPSS score for this vulnerability is < 1%, indicating a very low probability of exploitation, and the vulnerability is not listed in the CISA KEV catalogue. The attack requires user interaction with a malicious web page, so the primary vector is social engineering. It is inferred that no public exploits have been reported, so the risk remains moderate and the flaw should be mitigated promptly.
OpenCVE Enrichment
Debian DLA
Debian DSA