AI analysis
Google Chrome's FileSystem implementation contains a time-of-check to time-of-use (TOCTOU) race condition (CWE-367) that allows system access restrictions to be bypassed. Triggering it requires a crafted HTML page, an attacker who has already compromised the renderer process via a separate flaw, and social engineering to persuade the user, per Google's advisory. Successful exploitation lets the attacker bypass system access restrictions; Chromium rates the issue Medium severity. All Chrome users running versions earlier than 153.0.8010.52 are affected until they update. No public proof-of-concept, CISA KEV listing, or confirmed in-the-wild exploitation is known; the fix shipped in Chrome 153, which addresses 16 vulnerabilities including two critical ones.
What to do: Update Google Chrome to 153.0.8010.52 or later via chrome://settings/help and restart the browser; verify auto-update is enabled across your fleet. Because this flaw is designed to be chained from a compromised renderer plus user interaction, prioritize applying the full Chrome 153 release (16 fixes, including two critical ones). Check endpoint management or browser update reporting tools to confirm no clients remain on pre-153 builds.
Affected
| Google Chrome | all versions prior to 153.0.8010.52 |
Estimated exposure
mass≈3+ billion Chrome users (all builds before 153.0.8010.52) — Chrome is the world's dominant desktop browser with on the order of 3–4 billion active users, and every build prior to 153.0.8010.52 is affected, though practical exploitability is limited by the need to first compromise the renderer and…
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.