Impact
A use‑after‑free bug exists in Chrome’s password handling code on macOS versions before 149.0.7827.53. The flaw allows a remote attacker, who lures a user into performing specific UI gestures while visiting a crafted HTML page, to corrupt heap objects. Heap corruption can lead to arbitrary code execution or other severe failures.
Affected Systems
The vulnerability affects Google Chrome running on macOS. Any installation of Chrome prior to version 149.0.7827.53 is potentially vulnerable. Users of later releases are not affected.
Risk and Exploitability
The Chromium security team rates the issue as Critical, and the CVSS score of 7.5 indicates high severity. The EPSS score is not available and the vulnerability is not listed in the CISA KEV catalog. Exploitation requires the user to open a malicious webpage and perform certain UI gestures, suggesting a remote exploitation vector that is user‑dependent but feasible over the Internet.
OpenCVE Enrichment