Impact
A use‑after‑free flaw in the handling of browser extensions in Google Chrome on macOS allows an attacker to execute arbitrary code outside the browser sandbox through a crafted HTML page. The vulnerability is a classic use‑after‑free (CWE‑416) and can result in remote code execution with the privileges of the user who launches Chrome. The flaw emerges when Chrome frees memory associated with an extension before it is repurposed, leaving a dangling pointer that a malicious web page can exploit. The likely attack vector is a malicious site that serves the crafted page; based on the description, it is inferred that the attacker does not need elevated privileges or authentication besides convincing the user to load the malicious content.
Affected Systems
The vulnerability affects users running Google Chrome on macOS who are on the stable channel and have version numbers less than 153.0.8010.36. Only macOS builds are impacted; versions for Windows or Linux are not affected. The fix is included in Chrome 153.0.8010.36 and later releases.
Risk and Exploitability
The CVSS score of 9.6 indicates a severe risk, and the EPSS score of < 1% suggests a very low but non‑zero likelihood of exploitation. The vulnerability is not listed in the CISA KEV catalog. Based on the description, it is inferred that the attack can be performed by visiting a malicious web page, with no authentication or privileged access required. The exploitation would allow the attacker to run code with the privileges of the user’s Chrome session. The attack requires no additional software, only the delivery of the crafted HTML, thereby making the threat relatively straightforward for a determined attacker.
OpenCVE Enrichment
Debian DLA
Debian DSA