Impact
The vulnerability involves incorrect authorization handling within Chrome's FileAPI, allowing a remote attacker to bypass system access restrictions when a user opens a specifically crafted HTML page. An attacker would rely on social engineering to coerce upon success the user could gain unauthorized local system access. This weakness, identified as CWE-863, directly compromises user integrity and confidentiality by enabling privilege escalation within the browser context.
Affected Systems
Users of Google Chrome versions prior to 153.0.8010 apply to the desktop client, and it is inferred that any installations using the unstable or beta channels that have not incorporated the later patch would remain vulnerable.
Risk and Exploitability
The CVE has a CVSS score of 6.5, indicating moderate severity. The EPSS score is less than 1%, suggesting a very low exploitation probability, and the vulnerability is not listed in the CISA KEV catalog. Based on the description, the primary attack vector is a user interaction link, which requires social engineering rather than a technical network exploit. While the likelihood of widespread exploitation remains limited by this dependency on user action, a compromised user could gain elevated local privileges within Chrome. Installing the revisioned update mitigates the risk.
OpenCVE Enrichment
Debian DLA
Debian DSA