Omission of the .desktop filetype from the Safe Browsing checklist in SafeBrowsing in Google Chrome on Linux prior to 72.0.3626.81 allowed an attacker who convinced a user to download a .desktop file to execute arbitrary code via a downloaded .desktop file.
https://www.debian.org/security/2019/dsa-4395
https://chromereleases.googleblog.com/2019/01/stable-channel-update-for-desktop.html