Impact
This vulnerability arises from missing authorization checks in Google Chrome's FileSystem API. A crafted HTML page can trick the browser into granting file system access that should be restricted, allowing the attacker to read or modify arbitrary files on the host. The weakness is a missing authorization flaw (CWE‑862) and results in unauthorized file system access outside the browser sandbox.
Affected Systems
Affected systems are Google Chrome browsers older than version 153.0.8010.36. Any Windows, macOS, or Linux desktop installation running an unpatched browser can be impacted. The advisory lists only the Chrome product; no other vendor variants are noted.
Risk and Exploitability
The vulnerability has a CVSS score of 6.5, indicating medium severity within Chromium's own scoring and it is not listed in CISA KEV. The EPSS score is below 1 %, suggesting that the likelihood of widespread exploitation is low. Because the attack requires a crafted local HTML page served from an untrusted source, it is unlikely to be widely exploited without prior user interaction. Deploying the updated browser mitigates the risk entirely, and no public exploits are known.
OpenCVE Enrichment
Debian DLA
Debian DSA