Impact
A use‑after‑free flaw in Chrome’s GPU handling on macOS allows an attacker who has already compromised the renderer process to execute code beyond the sandbox by loading a specially crafted HTML page. The vulnerability is rated high by Chromium security, indicating that successful exploitation can lead to full system compromise if the sandbox is broken.
Affected Systems
The issue affects Google Chrome versions on macOS earlier than 149.0.7827.115. Users running those releases are vulnerable to the GPU‑related memory corruption flaw.
Risk and Exploitability
The EPSS score is currently unavailable and the vulnerability is not listed in CISA’s KEV catalog, but the high severity rating reflects the potential impact. An attacker would need to deliver a malicious HTML file to a Chrome instance with a compromised renderer process; the exploit path requires bypassing the renderer process sandbox through a GPU memory use‑after‑free.
OpenCVE Enrichment