Impact
A use‑after‑free flaw in the Views component of Google Chrome on macOS allows a remote attacker to execute arbitrary code outside the browser sandbox by loading a specially crafted HTML page. The vulnerability permits code execution on the victim’s machine, potentially compromising all data and privileges held by the user.
Affected Systems
Google Chrome for macOS versions earlier than 152.0.7977.65 are affected. The flaw resides in the Views layer of the browser and applies to any installation of the desktop stable channel of Chrome on a Mac operating system.
Risk and Exploitability
The issue is rated high severity, with a CVSS score of 9.6, according to Chromium security. EPSS data is not available, and it is not listed in the CISA KEV catalog, indicating no known widespread exploitation yet. The likely attack vector is a remote, web‑based attack: an adversary serves a malicious HTML document that causes the browser to free memory that is later accessed through an out‑of‑range pointer, elevating execution beyond the sandbox. Successful exploitation requires the user to load the crafted page, making it a user‑interaction dependent threat.
OpenCVE Enrichment
Debian DLA
Debian DSA