Use after free in Digital Credentials in Google Chrome on Mac prior to 149.0.7827.197 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
| Vendor | Product | Versions |
|---|---|---|
| chrome | 149.0.7827.197 |
Downstream vendors/products affected by this vulnerability
| Vendor | Product | Source | Confidence |
|---|---|---|---|
| apple | macos | cve_cpe | 95% |
| chrome | cert_advisory | 90% |
Updated vendor to Microsoft, added product Edge, and marked exploit availability and active exploitation as true.
Updated severity to CRITICAL, affected versions to include 149.0.7827.155, and clarified that no exploit is available.
Initial creation