Impact
A use‑after‑free flaw (CWE‑416) in Google Chrome’s Bluetooth subsystem on macOS can let a remote attacker escape the browser sandbox after a user visits a malicious web page and performs specific UI gestures. The vulnerability can give the attacker execution capability at the renderer process privilege, which is sufficient to break out of Chrome’s sandbox and potentially compromise the host operating system. The flaw requires user interaction with crafted content; without it the attacker cannot trigger exploitation.
Affected Systems
Google Chrome builds prior to 150.0.7871.47 on macOS are affected. Versions 150.0.7871.47 and later include the fix, eliminating the vulnerability.
Risk and Exploitability
The flaw carries a CVSS score of 9.6, indicating critical severity. The EPSS score is below 1%, showing a low estimated current probability of exploitation, yet the required user interaction means a determined attacker could succeed if they persuade a victim to visit the malicious page and perform the gestures. The vulnerability is not listed in the CISA KEV catalog as of this analysis.
OpenCVE Enrichment
Debian DLA
Debian DSA