Impact
A use‑after‑free condition exists in the audio subsystem of Google Chrome on macOS. If a compromised renderer process can exploit this flaw, an attacker who has already loaded a crafted HTML page can potentially escape the renderer sandbox and execute code with elevated privileges. The weakness is characterized by CWE‑416 and type‑based abuse (CWE‑825).
Affected Systems
The vulnerability affects Google Chrome versions prior to 151.0.7922.72 running on macOS. Any user using these earlier builds is exposed to the risk if a malicious web page can compromise the renderer process.
Risk and Exploitability
The CVSS score is 8.8, indicating high severity, while the EPSS score is below 1 %, suggesting a low probability of exploitation. The vulnerability is not listed in the CISA KEV catalog. Attackers would need to trick a user into loading a specially crafted web page that exploits the renderer process; once achieved, the sandbox escape could lead to local privilege escalation on the machine.
OpenCVE Enrichment
Debian DLA
Debian DSA