Impact
A use‑after‑free flaw was discovered in the Dawn renderer component of Google Chrome on macOS. The bug allows a remote attacker to potentially corrupt heap memory by providing a specially crafted HTML page. The Chromium severity rating is high, reflected in a CVSS score of 8.8. Based on the description, the potential impact could include a crash or other adverse result, but the specific outcome is not stated.
Affected Systems
The vulnerability affects Google Chrome on macOS for all versions prior to 149.0.7827.103. Any user employing those builds to view web content is potentially exposed.
Risk and Exploitability
The flaw requires a victim to open a malicious webpage in Chrome on a Mac. While no EPSS score is available and the vulnerability is not listed in CISA's KEV catalog, the CVSS score of 8.8 indicates a high severity and potential for heap corruption, indicating a meaningful risk. Based on the description, an attacker could host and serve a crafted page; this inference suggests a standard web‑based delivery vector is probable.
OpenCVE Enrichment