Impact
An interpretation conflict in the SafeBrowsing subsystem of Google Chrome on macOS allows a remote attacker to bypass local system access restrictions by delivering a specially crafted file. The flaw permits the circumvents expected safeguards, granting the victim’s user privileges that should have been blocked. The vulnerability is classified as CWE‑436, indicating a problem with data interpretation or handling. The maximum damage is limited to the rights of the account that executes the file, though repeated exposure could enable persistent access to local resources.
Affected Systems
Google Chrome running on macOS where the installed version is older than 153.0.8010.36. No specific sub‑version ranges are listed, only the prerelease cutoff before the final patch. Any older stable channel releases on the platform are potentially vulnerable.
Risk and Exploitability
The EPSS score is < 1% and the vulnerability is not listed in CISA’s KEV catalog, indicating no known widespread exploitation. The CVSS score of 6.5 suggests moderate severity, while the Chromium security severity is noted as low. A successful attack requires convincing a user to open a maliciously crafted file, after which the SafeBrowsing interpretation conflict permits local access to otherwise restricted resources. The risk is therefore confined to environments where users may be targeted by phishing or other social engineering tactics.
OpenCVE Enrichment
Debian DLA
Debian DSA