Impact
Chrome’s FileSystem API contains a missing authorization check that allows a remote attacker to craft an HTML page and trick a user into loading it, enabling the attacker to bypass system access restrictions and potentially read or write arbitrary files on the user’s machine. The weakness is categorized as an authorization flaw.
Affected Systems
Versions of Google Chrome before 153.0.8010.36 on the stable channel are impacted. Users who are still on these older releases are at risk unless they upgrade or apply other mitigations.
Risk and Exploitability
EPSS score is < 1%, indicating a very low probability of exploitation, and the vulnerability is not listed in the CISA KEV catalog, which suggests there are no known widespread exploits at this time. However, the attack requires social engineering and user interaction to load a crafted HTML page, indicating that successful exploitation depends on user behavior. The medium severity score reflects the potential for unauthorized file system access in a user’s context.
OpenCVE Enrichment
Debian DLA
Debian DSA