Impact
A use‑after‑free bug in Chrome’s GPU code can let an attacker that has already compromised the renderer process escape the browser sandbox by loading a specially crafted HTML page. This could give the attacker code‑execution or file‑system access on the host, as described by CWE‑416 and CWE‑825.
Affected Systems
Google Chrome for macOS versions prior to 151.0.7922.72 is affected.
Risk and Exploitability
The CVSS score of 5.8 classifies the vulnerability as medium, and the EPSS score indicates a very low likelihood of exploitation. The vulnerability is not listed in CISA’s KEV catalog. Exploitation requires a compromised renderer, so a purely remote or network‑based attack is unlikely without an additional exploit. Nonetheless, the impact of a successful sandbox escape is significant, justifying timely patching.
OpenCVE Enrichment
Debian DLA
Debian DSA