Impact
Chrome’s Tint component on macOS suffers from a memory‑corruption flaw that can be triggered by a crafted HTML page. The resulting buffer misuse permits a remote attacker to break out of the sandbox and run code with system privileges. This vulnerability falls under CWE‑119, highlighting improper handling of memory buffers.
Affected Systems
Google Chrome for macOS versions prior to 152.0.7977.65 are affected. Users of the stable channel on Mac computers must verify they are running a later release, as earlier versions contain the Tint flaw.
Risk and Exploitability
The flaw has a CVSS score of 8.8, indicating high severity, and an EPSS score of less than 1%, suggesting a low but nonzero probability of exploitation. Attackers would need network or user interaction to supply the malicious HTML—such as hosting a crafted web page or delivering a file via email. Once delivered, the experience is essentially remote code execution, making this a high‑risk vulnerability if unpatched. The vulnerability is not listed in CISA’s KEV catalog and no exploitation evidence has been reported.
OpenCVE Enrichment
Debian DLA
Debian DSA