Impact
A use‑after‑free vulnerability in Google Chrome’s Tabs component on macOS prior to version 155.0.8059.39 allows a remote attacker to craft an HTML page that can trigger a use after free, potentially letting the attacker execute code outside the browser sandbox. The flaw is a classic memory corruption bug (CWE‑416) that may compromise confidentiality, integrity, and availability of the compromised system if executed. The vulnerability is considered high severity in Chromium’s internal ranking.
Affected Systems
Google Chrome running on macOS users with versions earlier than 155.0.8059.39 are affected. Any user who visits a maliciously crafted web page while Chrome is running is potentially exposed.
Risk and Exploitability
The attack vector is remote: a malicious web page triggers the use‑after‑free. The CVSS score of 9.6 indicates a critical level of risk, and the vulnerability is not listed in the CISA KEV catalog. The potential for exploitation is significant. No specific exploitation example is provided, but the flaw allows arbitrary code execution outside the sandbox, making it a high‑risk issue for affected users.
OpenCVE Enrichment