Impact
An inappropriate implementation in Chrome’s WebAppInstalls component on macOS allows a remote attacker who has gained control of the renderer process to craft a malicious HTML file that can escape the sandbox. This flaw is identified as CWE‑693. Successful exploitation would let the attacker execute code with privileges higher than those of the renderer, potentially compromising the entire operating system.
Affected Systems
All installations of Google Chrome for macOS running versions earlier than 150.0.7871.47 are vulnerable. Users who have not upgraded to this or later releases remain at risk, including those on legacy builds that continue to ship older Chrome kernels.
Risk and Exploitability
The CVSS score of 9.6 indicates a severe vulnerability, but the EPSS score of less than 1% suggests that exploitation in the wild is unlikely. The flaw describes improper system capability limitations and insufficient access controls. The attack would require an attacker to first compromise the renderer process—typically via malicious web content—and then serve a specially crafted HTML page that triggers the sandbox escape. While the low EPSS indicates limited current exploitation, the high severity warrants prompt remediation.
OpenCVE Enrichment
Debian DLA
Debian DSA