Impact
A use‑after‑free condition in Google Chrome’s Bluetooth handling on macOS can lead to heap corruption, which may allow a remote attacker to execute arbitrary code (CWE‑1341, CWE‑416). The vulnerability is triggered by a specially crafted HTML page that causes the browser to access freed memory while processing Bluetooth data.
Affected Systems
Mac OS users running Google Chrome versions prior to 149.0.7827.103 are impacted. The flaw affects the standard desktop Chrome release on macOS, with the specific version boundary indicated by the stable channel update on June 2026.
Risk and Exploitability
The CVSS score of 8.8 indicates a high severity for this use‑after‑free bug. The vulnerability is listed in Chromium’s security advisories but does not yet have a publicly known exploit. It was not detected in the CISA KEV catalog, and EPSS score is <1%. The likely attack vector involves a remote attacker delivering a crafted HTML page that takes advantage of the Bluetooth implementation, leading to a use‑after‑free scenario. Because the flaw can result in arbitrary code execution and there is precedent for similar Chrome bugs being exploited, the risk remains significant pending the release of a fix.
OpenCVE Enrichment
Debian DSA