Impact
Chrome’s Safe Browsing implementation on macOS includes a policy bypass that allows a remote attacker to execute arbitrary code by delivering a malicious file. The vulnerability, identified as CWE-269 and CWE-494, is classified with a CVSS score of 8.8, indicating a high potential for compromising confidentiality, integrity, and availability, despite Chromium’s low severity label.
Affected Systems
Google Chrome running on macOS in any release prior to version 151.0.7922.72 is affected. Users who have not upgraded to this version remain vulnerable; no other operating systems or Chrome variants are explicitly listed as impacted.
Risk and Exploitability
With a CVSS rating of 8.8, the vulnerability represents a high risk to affected systems. The EPSS score of less than 1% suggests low probability of exploitation, and the vulnerability is not currently listed in the CISA KEV catalog. Based on the description, the likely attack vector involves an adversary delivering a malicious file that Chrome processes, such as via a user‑initiated download or local execution of a file. No public exploitation data has been observed, but the high severity warrants preventive action.
OpenCVE Enrichment
Debian DLA
Debian DSA