Impact
This vulnerability is a use‑after‑free flaw in the Bluetooth handling code of Google Chrome for macOS. An attacker who can already compromise the renderer process may deliver a crafted HTML page that exploits the freed memory and potentially escapes Chrome’s sandbox, leading to execution of arbitrary code. The weaknesses involve CWE‑416 and CWE‑825, both memory corruption defects that enable unauthorized access to resources.
Affected Systems
Google Chrome browsers running on macOS, any version prior to 149.0.7827.103, are affected. All earlier builds contain the vulnerable Bluetooth implementation and could be exploited when an attacker controls a renderer instance.
Risk and Exploitability
The CVSS score of 8.3 indicates a high severity, and Chromium rates this vulnerability as Critical, though it is not currently cataloged in CISA KEV. Because the exploit requires the renderer to be compromised first, the immediate ease of exploitation is limited; however, once renderer compromise is achieved, an attacker can leverage the use‑after‑free to escape the sandbox. The EPSS score of 0.00108, which is less than 1%, indicates a very low but non‑zero public exploitation probability.
OpenCVE Enrichment
Debian DSA