Impact
Chromium documents an authorization gap in the FileSystem interface of Google Chrome. A remote attacker who has already breached the renderer process and can entice a user to load a specially crafted HTML page may invoke the FileSystem API without proper permission checks. The flaw permits execution of arbitrary code outside the renderer sandbox, allowing the attacker to compromise system confidentiality, integrity, and availability. The weakness is classified as CWE‑862.
Affected Systems
The issue affects desktop editions of Google Chrome. Any build older than version 153.0.8010.36 is vulnerable. Users running these releases should verify their current version and update to the patched release.
Risk and Exploitability
Chromium rates the vulnerability as high severity with a CVSS score of 8.3. The EPSS score is below 1 % and the vulnerability is not listed in the CISA KEV catalog. Exploitation requires a prior compromise of the renderer process and a social‑engineering luring step to get the user to open the malicious HTML document. Once achieved, the attacker can run code with renderer‑level privileges and escape the sandbox. While the likelihood of a successful attack is moderate due to the prerequisite conditions, the potential impact is severe.
OpenCVE Enrichment
Debian DLA
Debian DSA