Inappropriate implementation in OS in Google Chrome on ChromeOS prior to 75.0.3770.80 allowed a remote attacker to perform arbitrary read/write via a malicious file. (Chromium security severity: Critical)
The product attempts to access a file based on the filename, but it does not properly prevent that filename from identifying a link or shortcut that resolves to an unintended resource.
Link | Tags |
---|---|
https://bugs.chromium.org/p/chromium/issues/detail?id=960109 | patch exploit vendor advisory issue tracking |
https://crbug.com/960109 | patch exploit vendor advisory issue tracking |