Impact
The vulnerability is a use‑after‑free flaw in Chrome’s GPU code on macOS that allows a remote attacker who has already compromised the renderer process to execute arbitrary code. The flaw stems from improper memory handling (CWE‑416) and an additional identified weakness (CWE‑825), giving the attacker full control over the victim’s machine. It has a high severity rating in Chromium’s internal review.
Affected Systems
Google Chrome running on macOS versions before 148.0.7778.216 is affected. Users of earlier Chrome builds on Mac should verify their installed version and upgrade if necessary.
Risk and Exploitability
The CVSS score is 7.5, but the EPSS score is not available, and the vulnerability is not listed in the CISA KEV catalog. The attack requires a compromised renderer process, which can be achieved by hosting a maliciously crafted page; this makes the threat primarily a crafted‑HTML exploitation scenario rather than a remote network intrusion.
OpenCVE Enrichment