Impact
A use‑after‑free bug was discovered in the Device class of Google Chrome on macOS. The flaw occurs when a crafted HTML page is rendered, freeing a resource that is still referenced by the browser. An attacker can exploit the dangling pointer to execute arbitrary code outside the Chrome sandbox, enabling full system compromise. The weakness is a classic memory‑management flaw, classified as CWE‑416, and the Chromium team rated it high seriousness.
Affected Systems
Google Chrome on macOS users running a version older than 153.0.8010.36 are impacted. The vulnerability affects the browser engine that processes HTML content on Mac desktops.
Risk and Exploitability
The flaw carries a high severity rating, with a CVSS score of 9.6. EPSS is below 1%, and it is not listed in the CISA KEV catalog. The most likely attack vector is a remote web page that an authenticated or unauthenticated user can open. Because the vulnerability allows execution outside the sandbox, the threat surface includes full system compromise if the attack succeeds.
OpenCVE Enrichment
Debian DLA
Debian DSA