Impact
A use‑after‑free bug (CWE‑416) exists in the Views component of Google Chrome on macOS prior to version 147.0.7727.138. When a crafted HTML page is rendered, an attacker can trigger heap corruption that may lead to arbitrary code execution. This vulnerability is identified as CWE‑416 and CWE‑825. The Chromium security team has rated the severity of this issue as high, indicating that successful exploitation allows an attacker to run code with user privileges or higher within the browser process.
Affected Systems
The vulnerability affects Google Chrome on macOS versions prior to 147.0.7727.138. The CVE description does not mention Windows or Linux; therefore, those platforms are not known to be impacted by this use‑after‑free flaw.
Risk and Exploitability
The CVSS score of 8.8 indicates a high severity classification, and the EPSS score is not available. The issue is not yet cataloged in the CISA KEV database. Exploitation requires a crafted HTML page; a remote attacker could lure a user to such a page, which may lead to code execution on the client machine. Due to the high severity and absence of a publicly available EPSS score, the exploitation probability remains uncertain but warrants immediate remediation.
OpenCVE Enrichment
Debian DSA