Impact
The flaw is an incorrect authorization check in the FileSystem component of Google Chrome, which could allow a remote attacker to execute arbitrary code outside the sandbox by delivering a specially crafted HTML page. This vulnerability represents a High severity issue within the Chromium security framework and is classified as CWE-863, indicating improper access control. The attack enables an attacker who can exploit user social engineering to run malware with elevated privileges on the victim’s machine.
Affected Systems
Google Chrome browsers older than version 152.0.7977.75 are susceptible, affecting all platforms where the stated version is deployed. Users on any operating system running this legacy Chrome build are at risk until an updated version is installed.
Risk and Exploitability
The vulnerability is exploitable remotely with a crafted HTML file and requires social engineering to convince a user to open or navigate to the malicious content. No EPSS score is currently available, and the issue is not listed in the CISA KEV catalog; however, its high severity and lack of mitigation in the sandbox suggest a significant risk. Until a patch is applied, the potential for widespread exploitation remains realistic, especially in environments where users download or view unknown files.
OpenCVE Enrichment