Impact
Use after free vulnerability in Chrome's Bluetooth handling on macOS allows remote attackers to craft an HTML page that triggers a deallocated object reference. By exploiting this flaw, an attacker can execute code outside the browser sandbox, gaining full control over the victim’s system. Because an attacker can deliver a malicious page through social engineering, the impact threatens confidentiality, integrity, and availability of the user’s machine.
Affected Systems
The flaw affects Google Chrome on macOS versions prior to 152.0.7977.65. Any user running a vulnerable Chrome installation on a Mac is at risk. No other platforms or browsers are listed as impacted.
Risk and Exploitability
The CVE has a CVSS score of 9.6 and is not listed in the CISA KEV catalog. EPSS data is unavailable, so the exact exploitation probability cannot be quantified, but sandbox escape indicates a high impact if triggered. The likely attack vector requires social engineering to deliver a malicious page that is opened in the vulnerable browser, enabling full system compromise.
OpenCVE Enrichment
Debian DLA
Debian DSA