Impact
This vulnerability arises from an incorrect authorization check within Chrome’s FileHandling component. A malicious HTML page can be crafted so that, when opened by a user, the browser bypasses system access restrictions and grants the attacker elevated privileges or access to local files. The flaw is an authorization bypass that could compromise confidentiality and integrity of user data.
Affected Systems
Google Chrome versions earlier than 153.0.8010.36 on all supported operating systems are affected. The issue is present in the stable channel, and all users running these versions are potentially vulnerable unless mitigated.
Risk and Exploitability
Exploit requires a remote attacker to convince a user to open a specially crafted page, typically via social engineering. The EPSS score is < 1% and the vulnerability is not listed in CISA KEV, but the CVSS score of 6.5 indicates medium severity, though Chromium’s assessment classifies it as low. While the technical risk level is low, the reliance on user interaction means that the exploit could still occur in environments where users are exposed to phishing or malicious web content.
OpenCVE Enrichment
Debian DLA
Debian DSA