Impact
An integer overflow exists in Google Chrome’s Safe Browsing module on macOS. The flaw allows a remote attacker to craft a malicious file that, when opened by the browser, triggers the overflow and causes Safe Browsing to incorrectly treat the file as safe. This misclassification enables navigation to URLs that would normally be blocked, effectively bypassing the browser’s protection. The vulnerability is classified as CWE‑472 and does not provide arbitrary code execution.
Affected Systems
macOS users running Google Chrome versions earlier than 150.0.7871.47 are affected. Devices upgraded to 150.0.7871.47 or later enjoy the fix.
Risk and Exploitability
The CVSS score of 8.1 indicates high severity, but the EPSS score of less than 1% and absence from the CISA KEV catalog suggest a low likelihood of current exploitation. Based on the description, an attacker must supply a malicious file—typically delivered via email, download, or file sharing—that is opened by the browser. Once processed, the attacker can navigate to otherwise blocked URLs. The flaw does not grant arbitrary code execution or system compromise, but it undermines the browser’s security controls.
OpenCVE Enrichment
Debian DLA
Debian DSA