Impact
Google Chrome versions prior to 153.0.8010.36 contained an incomplete cleanup routine for downloaded files, which allows a user who opens a specially crafted HTML page to bypass system access restrictions. This flaw is a type of improper cleanup that can lead to unauthorized elevation of privileges or data exposure if the attacker succeeds. The impact is that a malicious page, delivered over an untrusted network, could cause a user to unintentionally gain higher level file system access than intended. The underlying weakness is identified as CWE-459.
Affected Systems
The affected product is Google Chrome for desktop, affecting all platforms where Chrome is installed. Versions older than 153.0.8010.36 are vulnerable.
Risk and Exploitability
The CVSS score of 6.5 indicates medium severity, reflecting the need for user interaction and a social‑engineering component. The EPSS score is < 1%, and the vulnerability is not listed in the CISA KEV catalog. Exploitation requires an attacker to lure a user into opening a malicious HTML page, so the real‑world risk depends on user awareness and network exposure. However, because the flaw enables a bypass of system access restrictions, the potential impact is significant for any environment that relies on Chrome for browser access.
OpenCVE Enrichment
Debian DLA
Debian DSA