Impact
vulnerability is a use‑after‑free flaw in the audio subsystem of Google Chrome on macOS before version 148.0.7778.96. A specially crafted HTML page can cause the browser to free audio objects and subsequently reuse the same memory region, allowing attacker‑supplied code to execute inside the sandboxed renderer process. The flaw is classified as CWE‑416, and the impact is confined to code execution confined within the sandboxed environment. While the sandbox prevents immediate escalation to the host, the execution of arbitrary code remains a significant security risk.
Affected Systems
The defect affects macOS users running any build of Google Chrome whose version is older than 148.0.7778.96. This includes all channel releases of Chrome for macOS that were compiled before that revision.
Risk and Exploitability
The CVSS score of 8.8 indicates a high severity rating. EPSS data is not available and the vulnerability is not listed in CISA KEV, implying that no publicly documented exploits exist yet. Inferred attack vectors involve an attacker delivering a malicious HTML page through phishing or a compromised website, which can trigger the use‑after‑free during media playback, leading to code execution inside the sandboxed renderer.
OpenCVE Enrichment
Debian DSA