Impact
The vulnerability is an insecure cryptographic implementation in Google Chrome for macOS, identified as CWE‑501. A remote attacker who can compromise the renderer process may deliver a specially crafted HTML page that triggers a sandbox escape, allowing code execution beyond the browser's isolation. The impact is a privilege escalation that can compromise the host system and jeopardise confidentiality, integrity, and availability.
Affected Systems
Google Chrome on macOS versions prior to 151.0.7922.72 are affected. Users running these releases are at risk when a malicious web page can exploit the compromised renderer.
Risk and Exploitability
The CVSS score of 9.6 indicates high severity, while the EPSS score of less than 1% suggests a low current likelihood of exploitation. The vulnerability is not listed in the CISA KEV catalog. Likely attack vectors involve serving a malicious HTML payload that escalates privileges once the renderer process is compromised.
OpenCVE Enrichment
Debian DLA
Debian DSA