Impact
The vulnerability is a use‑after‑free flaw located in the TabStrip component of Google Chrome on macOS. An attacker who has already compromised the renderer process can supply a specially crafted HTML page that triggers the freed memory use, allowing the attacker to bypass the browser's sandbox and execute code with higher privileges. This results in a sandbox escape, a type of privilege escalation that can compromise system stability and confidentiality.
Affected Systems
Affected systems are installations of Google Chrome for macOS with a version earlier than 151.0.7922.137. The flaw exists only in the stable channel before that specific build. Users on other operating systems or newer Chrome releases are not impacted.
Risk and Exploitability
The CVSS score of 8.3 reflects a high severity impact, but the very low EPSS score of 0.25% indicates a low probability of exploitation in the wild, and the vulnerability is not currently listed in CISA’s KEV catalog. Nevertheless, the potential for remote sandbox escape makes the risk moderate to high after considering the severity, requiring timely patching. The attack path requires an attacker to compromise the renderer, so exploitation likely originates from malicious web content or phishing sites.
OpenCVE Enrichment
Debian DLA
Debian DSA