Impact
A use‑after‑free flaw in Google Chrome on macOS before version 151.0.7922.169 allows an attacker to trigger arbitrary code execution outside the browser sandbox when a user visits a crafted HTML page. The vulnerability occurs when the browser accesses a memory object that has already been freed, enabling malicious code to run with full system privileges.
Affected Systems
Google Chrome browsers on macOS older than 151.0.7922.169 are affected. Newer releases and other operating systems are not impacted.
Risk and Exploitability
The CVSS score of 8.8 indicates a high‑impact vulnerability. The EPSS score of <1% suggests the risk of exploitation is low at present, and the issue is not listed in the CISA KEV catalog. Attackers exploit this flaw by socially engineering users into opening a malicious HTML page, at which point the use‑after‑free triggers and allows execution of arbitrary code outside the sandbox. The vulnerability is associated with CWE‑416 and also references CWE‑825, though the description does not elaborate further on primitive‑data misuse beyond the memory corruption inherent to use‑after‑free.
OpenCVE Enrichment
Debian DLA
Debian DSA