Impact
Google Chrome for macOS contains an object lifecycle flaw (CWE‑664) and an improper authorization issue (CWE‑825) in the WebShare component that allows a malicious web page to cause arbitrary code execution. The vulnerability requires a victim to load a specially crafted page and interact with the browser’s UI in a specific way, after which the browser will execute unintended code. The flaw is classified as critical severity by Chromium’s security team.
Affected Systems
This issue affects Google Chrome on macOS releases prior to version 148.0.7778.168. The affected product is the Chrome browser for Mac, and only installations that have not applied the latest stable update are vulnerable.
Risk and Exploitability
The CVSS score of 8.8 indicates high severity. The EPSS score is not available and the vulnerability is not listed in the CISA KEV catalog, indicating no known large‑scale exploitation yet. However, the description labels it as critical, suggesting that if an attacker can lure a user to interact with a malicious page, arbitrary code execution could occur. Because the exploitation path relies on user engagement with a crafted web page and specific UI gestures, the likelihood of successful exploitation may be moderate but still significant for targeted attacks.
OpenCVE Enrichment
Debian DSA