Impact
The flaw involves incorrect resolution of references within the FileSystem component of Google Chrome. This weakness, classified as CWE‑706, allows a remote attacker who can trick a user into opening a specially crafted HTML page to achieve execution of arbitrary code outside the browser sandbox. The impact is the potential compromise of the entire host system if code runs with elevated privileges, and it bypasses the browser’s security boundaries.
Affected Systems
Chrome Desktop versions prior to 153.0.8010.36 are affected. Users running any older stable channel or pre‑stable releases may be vulnerable; updating to the 153.0.8010.36 build or later removes the defect.
Risk and Exploitability
Chromium’s own severity rating for this issue is Medium, but the CVSS score is 9.6. The EPSS score is less than 1%, and the vulnerability is not listed in KEV. The attack requires social engineering to deliver the malformed HTML, so the likelihood of exploitation depends on user susceptibility and attacker resources. Without further evidence of active exploitation, the risk remains moderate until the patch is applied.
OpenCVE Enrichment
Debian DLA
Debian DSA