Impact
The vulnerability is a race condition (CWE-367) in the FileSystem module of Google Chrome that can be exploited by an attacker who has already gained partial control of the renderer process. By creating a specially crafted HTML page the attacker can race privileged and unprivileged threads, causing the renderer to access files outside its sandbox. This bypasses the operating‑system access restrictions and allows the attacker to read or modify local files, compromising the confidentiality and integrity of the user’s data.
Affected Systems
Google Chrome browsers on desktop in the stable channel running any build prior to version 153.0.8010.52. The flaw was fixed in the 153.0.8010.52 release and all later revisions.
Risk and Exploitability
The CVSS score of 3.1 indicates low overall severity, and the EPSS score less than 1% shows a very small chance of real‑world exploitation. Because the flaw requires a renderer process compromise first, the likelihood of a successful attack is low unless the attacker already succeeded in a social‑engineering attack to trigger the renderer. The vulnerability is not listed in CISA’s KEV catalog, indicating no known active exploitation. An attacker could obtain renderer control by convincing a user to load a targeted HTML page, after which the race condition would enable escape from sandbox file restrictions.
OpenCVE Enrichment
Debian DLA
Debian DSA