Inappropriate implementation in image-burner in Google Chrome OS prior to 59.0.3071.92 allowed a local attacker to read local files via dbus-send commands to a BurnImage D-Bus endpoint.
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2017-5084.json"
[ { "events": [ { "introduced": "0" }, { "fixed": "59.0.3071.92" } ] } ]