Impact
This vulnerability is a use‑after‑free bug in the CameraCapture module of Chrome on macOS. When a crafted HTML page triggers the deallocation of a camera resource, an attacker can escape Chrome’s renderer sandbox and potentially execute code with elevated privileges, compromising device confidentiality, integrity, and availability.
Affected Systems
Google Chrome on macOS versions prior to 150.0.7871.128 are affected. The issue has been reported in the stable channel and impacts the CameraCapture component.
Risk and Exploitability
The CVSS base score of 9.6 indicates a severe risk, but the EPSS score is less than 1% suggesting a low probability of widespread exploitation at present. The vulnerability is not listed in the CISA KEV catalog. The attack vector is remote: a malicious HTML page opened or rendered in Chrome on an affected Mac can trigger the use‑after‑free to escape the sandbox.
OpenCVE Enrichment
Debian DLA
Debian DSA