Impact
The vulnerability arises from incorrect authorization controls in Chrome’s FileSystem API, which allow a remote attacker who has compromised the renderer process to bypass site isolation when a crafted PDF is opened. This flaw (CWE-863) may enable access to resources belonging to other sites or contexts within the browser.
Affected Systems
Google Chrome installations running a version earlier than 153.0.8010.36 are affected. The flaw manifests when a malicious PDF is opened after the renderer process is compromised.
Risk and Exploitability
The CVSS base score of 8.1 indicates high severity. Exploitation requires a prior compromise of the renderer process, typically via a malicious PDF file. The EPSS score of <1% indicates a very low likelihood of exploitation in the wild, and the vulnerability is not listed in the CISA KEV catalog. Consequently, systems that keep Chrome updated face moderate overall risk, while those that process untrusted PDFs or run outdated Chrome versions are at higher risk.
OpenCVE Enrichment
Debian DLA
Debian DSA