Impact
A use‑after‑free flaw in Chrome’s Safebrowsing component on macOS lets a remote attacker execute arbitrary code outside the browser sandbox by loading a specially crafted HTML page. The vulnerability can be triggered via social engineering, granting the attacker full control of the victim’s machine and compromising confidentiality, integrity, and availability.
Affected Systems
Google Chrome running on macOS versions earlier than 152.0.7977.65 are affected. The bug exists in the Safebrowsing feature and impacts all users of that version.
Risk and Exploitability
Chromium categorizes the issue as Critical, with a CVSS score of 9.6 and an EPSS score of not available. The flaw is remotely exploitable through a web page; a malicious site can deliver the crafted content. No known public exploits are documented and the vulnerability is not listed in the CISA KEV catalog. Given the critical severity, the risk remains high until affected browsers are updated.
OpenCVE Enrichment
Debian DLA
Debian DSA