Impact
The vulnerability is a use‑after‑free flaw in the Bluetooth handling code of Google Chrome on macOS. An attacker can trigger the fault by presenting a specially crafted peripheral to the browser, causing the program to access freed memory and execute arbitrary code. Chromium rated the issue as critical, and the flaw threatens confidentiality, integrity, and availability for any user who has Chrome running with Bluetooth enabled.
Affected Systems
Google Chrome on macOS versions prior to 149.0.7827.103 are affected. Any Mac system that runs an impacted Chrome build with Bluetooth connections enabled is vulnerable. Versions 149.0.7827.103 and later include the fix.
Risk and Exploitability
The exploit requires a malicious Bluetooth peripheral in proximity and the victim to have Chrome listening for devices. Although the EPSS score is not available and the vulnerability is not listed in KEV, its CVSS score of 8.8 and the local‑range attack vector suggest a high likelihood of exploitation. Because the condition for execution is proximity to a Bluetooth device and no defensive filtering is available, the risk remains high.
OpenCVE Enrichment