Impact
This flaw is a use‑after‑free defect in the Payments component of Google Chrome that allows a crafted HTML page to corrupt heap memory. The resulting heap corruption can be leveraged by a remote attacker to execute arbitrary code or otherwise compromise the integrity of the browser process. The weakness is a classic use‑after‑free scenario and involves improper handling of payment data (CWE‑416, CWE‑825).
Affected Systems
Any device running Google Chrome before version 149.0.7827.103 is vulnerable. The issue appears in all platforms that ship the affected release.
Risk and Exploitability
The CVSS score of 8.8 indicates high severity. The EPSS score indicates a very low but nonzero likelihood of exploitation (approximately 0.1%), and the Chromium team has rated the vulnerability as High, making the risk surface significant when an untrusted website can deliver a malicious HTML payload. An attacker could target a user browsing the web, and the threat model assumes the victim is running the unpatched browser. The absence of a KEV listing does not diminish the potential impact, and the flaw remains exploitable until an update is applied.
OpenCVE Enrichment
Debian DSA