Impact
An integer overflow in Google Chrome’s Safe Browsing module on macOS allows a remote attacker to craft a malicious file that, when opened, causes Safe Browsing to misclassify the file as safe and permits navigation to URLs that would otherwise be blocked.
Affected Systems
macOS users running Google Chrome versions earlier than 150.0.7871.47 are affected; upgrading to 150.0.7871.47 or later removes the flaw.
Risk and Exploitability
The CVSS score of 8.1 indicates high severity, yet the EPSS score of less than 1% and absence from the CISA KEV catalog suggest a low likelihood of exploitation. Exploitation requires the delivery of a malicious file, typically via email, download, or file sharing, that is opened by the browser, after which the attacker can navigate to otherwise blocked URLs. No arbitrary code execution or system compromise results from the vulnerability.
OpenCVE Enrichment
Debian DLA
Debian DSA