Impact
A use-after-free flaw in Chrome's Network code on macOS lets a remote attacker, usually via a socially engineered malicious extension, run arbitrary code outside the sandbox. This can compromise confidentiality, integrity, and availability of the system, because the attacker gains code execution rights in the browser environment.
Affected Systems
Google Chrome browsers on macOS that are earlier than version 152.0.7977.65 are affected. The flaw existed in all releases prior to 152.0.7977.65, so any Mac user running those versions is at risk.
Risk and Exploitability
The crash is triggered by a crafted extension, so the attack requires the user to install or enable that extension—an element of social engineering. The EPSS score is < 1%, indicating a very low probability of public exploitation. The vulnerability is not in CISA's KEV catalog. Nevertheless, it remains a remote code‑execution flaw, and if a malicious extension is installed the attacker can run code with browser process permissions, leading to full system compromise. The CVSS score is 9.6, indicating a very high severity.
OpenCVE Enrichment
Debian DLA
Debian DSA