Impact
A use‑after‑free flaw (CWE‑416) in Google Chrome’s Payments component allows a maliciously crafted HTML page to trigger heap corruption when a user performs specific UI gestures. The victim’s interaction can lead to a corrupted heap that may cause crashes or other unpredictable behavior; the public description does not confirm arbitrary code execution, but a heap corruption of this type can potentially subvert program logic or create a crash state that may be leveraged in further attacks. The vulnerability is present in all Chrome builds before version 150.0.7871.115 and requires the user to open a malicious page and trigger the payment UI.
Affected Systems
All installations of Google Chrome using a version earlier than 150.0.7871.115 are affected; no more granular version information is provided in the data.
Risk and Exploitability
The CVSS score of 7.5 and an EPSS score of less than 1% indicate a moderate likelihood of exploitation, and the vulnerability is not listed in the CISA KEV catalog. Exploitation requires a victim to open a malicious page and interact with the Payment UI, indicating that user interaction is necessary. No evidence of active exploitation but the high severity rating justifies prompt remediation.
OpenCVE Enrichment
Debian DLA
Debian DSA