> Do I have to tell users to download and run some executable?
Well, yes.
The alternative is to give any malicious ad the ability to drive-by-download malware onto your machine.
Well, yes.
The alternative is to give any malicious ad the ability to drive-by-download malware onto your machine.
A malicious ad would probably have an easier time tricking you into downloading and running an executable, which is something that has actually happened many times IRL. Worry about that before worrying about theoretical exploits that nobody has actually exploited in an API shipped in the world's most popular web browser for the past 6 years.
https://web.dev/patterns/files/open-a-directory
At least it got the number of files in the selected directory including Program Files and Windows\System32
I didn't click upload, so ...
None.
Because I don't use Chrome.
It's spyware.