Impact
A use‑after‑free defect in the Dawn rendering engine of Google Chrome on macOS predates version 150.0.7871.46. The flaw lets a remote attacker deliver a crafted HTML page that can trigger a memory corruption, resulting in a sandbox escape. If an attacker gains escape, they could execute code with the privileges of the logged‑in user, compromising confidentiality, integrity, and potentially availability of the entire system.
Affected Systems
All users running Google Chrome on macOS with versions earlier than 150.0.7871.46 are affected.
Risk and Exploitability
The advisory rates the vulnerability as high‑severity with a CVSS score of 9.6. The EPSS score is below 1 %, indicating a very low likelihood of exploitation at this time. It is not listed in the CISA KEV catalog. The attack would require a browser rendering a crafted HTML page, typically via a malicious website or local file, and relies on a use‑after‑free bug. No known exploit is currently publicly available, but the potential impact justifies immediate patching.
OpenCVE Enrichment
Debian DLA
Debian DSA