Impact
A use‑after‑free flaw exists within the Passwords component of Google Chrome on macOS. When a user is tricked into performing specific UI gestures—such as clicking, scrolling, or typing—while viewing a crafted HTML page, the vulnerability can be triggered to execute arbitrary code. The flaw is categorized as CWE‑416 and is rated critical by Chromium, indicating that a successful exploitation grants full code execution in the user’s browser context.
Affected Systems
Google Chrome running on macOS versions earlier than 149.0.7827.53 is vulnerable. Only the Mac implementation of Chrome is affected; no other platforms are listed.
Risk and Exploitability
The vulnerability requires a remote attacker to supply a malicious web page and convince an end user to interact with it, so the attack surface is limited to users who visit compromised sites. The CVSS score is 7.5, the EPSS score is currently not available, and the issue is not listed in the CISA KEV catalog. Despite the lack of exploit probability metrics, the high severity of the flaw and the ability to run code in the users’ process make it a high‑risk vulnerability for systems that remain on unsupported Chrome releases.
OpenCVE Enrichment