Impact
A use‑after‑free flaw exists in Chrome’s Views code on macOS. When a specially crafted HTML page is displayed, the memory freeing bug enables an attacker to run code outside of Chrome’s sandbox. The impact is full system compromise, allowing an attacker to execute arbitrary instructions as the current user. This is a high‑severity vulnerability as it bypasses the browser’s isolation safeguards.
Affected Systems
The flaw affects Google Chrome on macOS versions prior to 152.0.7977.65. Users running any older stable channel on a Mac computer are vulnerable until the issue is patched.
Risk and Exploitability
Because the flaw requires the delivery of a crafted HTML page, the likely attack vector is a remote “drive‑by” mechanism such as a malicious website or a targeted phishing email that opens a link. The CVSS score is 9.6, indicating a high‑severity risk. No exploitation probability is listed in EPSS, and the vulnerability is not included in the CISA KEV catalog, suggesting it is not a known widely‑used exploit yet. Nonetheless, the ability to escape the sandbox means the potential damage is severe. Even without an active exploit, the flaw warrants prompt patching to eliminate the risk of future exploitation.
OpenCVE Enrichment
Debian DLA
Debian DSA