Impact
The flaw is a use‑after‑free (CWE‑416) in the WebUSB implementation of Google Chrome on macOS. Based on that a local attacker who can supply a malicious USB peripheral that speaks the WebUSB protocol can trigger the browser to free a memory buffer and then reuse it with attacker‑controlled data, allowing execution of arbitrary code in the context of the user who is running Chrome.
Affected Systems
Google Chrome version 150.0.7871.47 and earlier on macOS.
Risk and Exploitability
The CVSS score is 7.8, and the EPSS score is below 1 %. The vulnerability is not currently listed in the CISA KEV catalog. Based on the description, it is inferred that exploitation requires the attacker to have physical or local access to a device that communicates via WebUSB. Successful exploitation results in code execution with the privileges of the logged‑in user.
OpenCVE Enrichment
Debian DLA
Debian DSA