Impact
The vulnerability is a use‑after‑free flaw (CWE‑416) in the WebUSB implementation of Google Chrome on macOS. Before build 150.0.7871.47 the bug allows a local attacker to issue commands that free a referenced memory buffer and then cause Chrome to interpret attacker‑controlled data while the buffer is still in use, leading to arbitrary code execution in the context of the user running the browser.
Affected Systems
Google Chrome version 150.0.7871.46 and earlier on macOS installations.
Risk and Exploitability
The CVSS score of 7.8 reflects the severity of the vulnerability, while the EPSS score is below 1 % indicating a low probability of exploitation in the wild. The issue is not listed in the CISA KEV catalog. Based on the description it is inferred that the attacker must have local access to a USB peripheral that can communicate with Chrome’s WebUSB interface; successful exploitation would give code‑execution privileges to the logged‑in user.
OpenCVE Enrichment
Debian DLA
Debian DSA