Impact
Missing authorization in Chrome’s FileSystem API before version 153.0.8010.36 allows a remote attacker who has already compromised the renderer process to read cross‑origin data through a crafted HTML page. The flaw enables the reader to retrieve confidential data that was otherwise restricted to the page’s origin.
Affected Systems
Google Chrome versions earlier than 153.0.8010.36 are affected. Users running any prior stable channel release are at risk until the update to 153.0.8010.36 or later is applied.
Risk and Exploitability
The vulnerability has a CVSS base score of 3.1, indicating a low severity impact. Exploitation requires that the attacker first gain control of the renderer process; after that, a malicious HTML page can be served to read data. No publicly documented exploits exist and the EPSS score is <1%. The flaw is not listed in the CISA KEV catalog. Because the attack vector necessitates process compromise, the likelihood of widespread exploitation is limited, but sufficient to warrant timely remediation.
OpenCVE Enrichment
Debian DLA
Debian DSA