Impact
A use‑after‑free bug in the Views component of Google Chrome on macOS allows a remote attacker to execute arbitrary code by serving a specially crafted HTML page. The flaw is a classic off‑by‑one memory misuse (CWE-416) that can overwrite program data after free. If exploited, the attacker can run code with the privileges of the Chrome process, potentially escalating to full system compromise.
Affected Systems
Google Chrome versions earlier than 149.0.7827.103 running on macOS are vulnerable. The impact is limited to the user running the affected Chrome instance. No other operating systems or desktop branches are mentioned.
Risk and Exploitability
The CVSS score of 8.8 indicates a High severity, although EPSS data is not available and the vulnerability is not listed in the CISA KEV catalog. Attackers would need to lure the victim to a malicious web page that contains the crafted HTML, a realistic scenario for phishing or malicious advertising campaigns. Once the exploit is triggered, any code can be executed within the Chrome process.
OpenCVE Enrichment