Impact
A use‑after‑free bug (CWE‑416) exists in the Views component of Google Chrome on macOS prior to version 147.0.7727.138. When a crafted HTML page is rendered, an attacker can trigger heap corruption that may lead to arbitrary code execution. The Chromium security team has rated the severity of this issue as high, indicating that successful exploitation allows an attacker to run code with user privileges or higher within the browser process.
Affected Systems
The vulnerability affects Google Chrome on macOS versions prior to 147.0.7727.138. The CVE description does not mention Windows or Linux; therefore, those platforms are not known to be impacted by this use‑after‑free flaw.
Risk and Exploitability
The EPSS score is not available, but the vulnerability is listed as high severity and is not yet cataloged in the CISA KEV database. Exploitation requires a crafted HTML page; a remote attacker could lure a user to such a page, leading to potential code execution on the client machine. The lack of an EPSS score means the probability of exploitation is uncertain, yet the high severity and potential to break out of the browser sandbox justify urgent remediation.
OpenCVE Enrichment