Impact
A use-after-free defect in the Dawn rendering engine of Google Chrome on macOS allows a remote attacker to potentially escape the browser sandbox by delivering a crafted HTML page. This issue corresponds to CWE-416, use-after-free.
Affected Systems
Google Chrome on macOS versions earlier than 150.0.7871.46.
Risk and Exploitability
The CVSS score of 9.6 demonstrates high severity. The EPSS score indicates a probability of exploitation below 1 %. The vulnerability is not listed in the CISA KEV catalog. A remote attacker can trigger the flaw by having the browser render a malicious HTML page. No publicly documented exploit is mentioned.
OpenCVE Enrichment
Debian DLA
Debian DSA