Impact
The vulnerability resides in the lack of authorization checks within Google Chrome's FileSystem API. An attacker who has already obtained code execution in the renderer process can serve a crafted HTML page that bypasses the browser's same‑origin policy, allowing the attacker to read, write, or delete arbitrary files on the victim’s system. This breach can lead to data theft, tampering, or the delivery of malicious content, thereby impacting confidentiality, integrity, and availability.
Affected Systems
The impacted vendor is Google, specifically the Chrome browser. All releases prior to version 152.0.7977.75 are affected, including any derivative Chromium‑based browsers that have not installed the specified update.
Risk and Exploitability
Chromium assigns a low severity to this issue, with a CVSS base score of 3.1. The EPSS score is < 1%, and the vulnerability is not listed in CISA KEV, indicating a modest likelihood of exploitation. However, the flaw requires that an attacker already gain code execution inside the renderer process—a prerequisite that considerably limits the attack surface. Nevertheless, organizations still should consider remediation promptly.
OpenCVE Enrichment
Debian DLA
Debian DSA