Impact
A flaw in Google Chrome’s FileSystem API lets a remote attacker craft an HTML page that, when opened by a user, bypasses operating‑system file access restrictions. The vulnerability stems from improper privilege management (CWE‑266) and improper privilege assignment (CWE‑269). When an end‑user interacts with the malicious page and grants the necessary permissions, the attacker can read or modify local files without obvious user consent, effectively elevating privileges within the user's environment.
Affected Systems
Google Chrome users on any operating system running a release older than 152.0.7977.65 are affected. The issue surfaces wherever the FileSystem API is enabled, which includes Windows, macOS, Linux, and other Chrome-supported platforms. Users who are tricked into opening a crafted page are at risk.
Risk and Exploitability
The CVSS score of 4.3 indicates medium severity, while an EPSS score of less than 1 % points to a low likelihood of widespread exploitation. The vulnerability is not listed in CISA’s KEV catalog. Exploitation requires social engineering to persuade a user to open a malicious page; once that interaction occurs, the path to privilege escalation is straightforward and does not involve additional technical prerequisites.
OpenCVE Enrichment
Debian DLA
Debian DSA