Use of extended attributes in downloads in Google Chrome prior to 72.0.3626.81 allowed a local attacker to read download URLs via the filesystem.
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2018-20073.json"
[ { "events": [ { "introduced": "0" }, { "fixed": "72.0.3626.81" } ] } ]