Impact
Improper input validation in the FileAPI component of Google Chrome allows an attacker who has already compromised the renderer process to execute arbitrary code outside the sandbox. The flaw stems from a failure to sanitize user‑supplied data before it is processed by the FileAPI, giving the attacker a vehicle for code execution once the renderer has been subverted. This is a classic validation or sanitization failure (CWE‑20).
Affected Systems
Google Chrome versions prior to 153.0.8010.36 on all supported platforms are affected. Any installation that has not yet been updated to 153.0.8010.36 or later contains the vulnerable code and may be exploited if the renderer process can be compromised.
Risk and Exploitability
The Chromium advisory now assigns a CVSS score of 8.3, indicating a High severity. The EPSS score is less than 1 percent, reflecting a very low but nonzero probability of exploitation. The vulnerability is not listed in CISA KEV, suggesting no known active exploitation. Exploitation still requires the attacker to already control the renderer process, a high‑barrier scenario. Nevertheless, the potential impact is remote code execution outside the browser sandbox, warranting prompt remediation.
OpenCVE Enrichment
Debian DLA
Debian DSA