Impact
An incorrect type conversion or cast occurs in the Safebrowsing component of Google Chrome on macOS before version 153.0.8010.36. When a remote attacker delivers a specially crafted file, the improper conversion allows the application to treat the file data in a way that bypasses defined system access restrictions. This flaw reduces the program’s ability to enforce expected constraints.
Affected Systems
Users running Google Chrome on macOS with versions earlier than 153.0.8010.36 are affected. Only the stable channel of Chrome on macOS is mentioned; no other operating systems or product channels are listed.
Risk and Exploitability
The flaw has a CVSS score of 4.3, an EPSS below 1%, and is not in the CISA KEV catalog. The vulnerability can be exploited remotely via a crafted file delivered to a user. It allows bypassing system access restrictions. Based on the description, it is inferred that such a bypass might enable an attacker to perform unauthorized system operations, though the description does not explicitly state privilege escalation.
OpenCVE Enrichment
Debian DLA
Debian DSA