Impact
The vulnerability is a use‑after‑free flaw in the Views component of Google Chrome on macOS, which allows a remote attacker to craft a malicious HTML page that triggers execution of arbitrary code outside the browser sandbox. The flaw can lead to full system compromise because the attacker obtains privileges beyond the sandbox.
Affected Systems
Google Chrome browsers running on macOS, versions earlier than 152.0.7977.65. Devices using these builds are at risk until an update is applied.
Risk and Exploitability
Chromium labels this issue as Critical and the CVSS score is 9.6. No EPSS score is currently available, and the vulnerability is not listed in the CISA KEV catalog. The likely attack vector is a remote exploitation via a crafted HTML page served over the network, with no local or privileged user involvement.
OpenCVE Enrichment
Debian DLA
Debian DSA