Incorrect reference resolution in FileSystem in Google Chrome prior to 153.0.8010.36 allowed a remote attacker leveraging social engineering to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Medium)
The product uses a name or reference to access a resource, but the name/reference resolves to a resource that is outside of the intended control sphere.
| Name | Vendor | Start Version | End Version |
|---|---|---|---|
| Chrome | * | 153.0.8010.36 (excluding) | |
| Chromium-browser | Ubuntu | upstream | * |