Impact
The vulnerability is a use‑after‑free flaw in the File Input handling of Google Chrome on macOS, identified as CWE-416, and it also involves resource management issues identified as CWE-825. A remote attacker who convinces a user to perform specific UI gestures on a crafted HTML page can potentially escape the browser sandbox and execute code with the privileges of the logged‑in user. The flaw can be triggered after the browser reclaims memory, leading to execution of arbitrary code; the Chromium security severity is listed as Medium.
Affected Systems
Google Chrome version 149.0.7827.53 and earlier on macOS are affected. All installations of Chrome on macOS not upgraded beyond the specified version are at risk.
Risk and Exploitability
The EPSS score is <1% and the vulnerability is not listed in CISA’s KEV catalog, but the high CVSS score of 9.6 indicates a critical impact. Exploitation requires a crafted HTML page, user interaction, and a victim’s device running a vulnerable Chrome instance on macOS. The attack would allow the attacker to break sandbox confinement, enabling remote code execution with the privileges of the logged‑in user, taking advantage of both CWE‑416 and CWE‑825 weaknesses.
OpenCVE Enrichment
Debian DSA