Impact
The vulnerability stems from insufficient validation of untrusted input within the Payments subsystem of Google Chrome. An attacker who can supply crafted HTML content to a compromised renderer process could potentially escape the renderer sandbox and gain uncontrolled code execution rights on the device. This flaw maps to input validation weaknesses (CWE‑20) and content parsing issues (CWE‑1289). Though the overall security severity is rated Medium by Chromium, the potential for remote code execution renders it critical for end‑users.
Affected Systems
Google Chrome versions prior to 151.0.7922.72 on all supported operating systems are affected. The flaw is present in the Payments module and is triggered when a renderer process receives maliciously crafted web content. All installations that have not applied the announced update are vulnerable.
Risk and Exploitability
The CVSS score of 9.6 indicates high severity, but the EPSS score of less than 1% suggests a low probability of exploitation in the wild. The vulnerability is not listed in the CISA KEV catalog, implying that it is not currently a known exploited target. An attacker would need to first compromise the renderer process—often requiring prior compromise of the device or social engineering—before attempting the sandbox escape. Once successful, the attacker could execute arbitrary code with the privileges of the user profile, leading to full system compromise.
OpenCVE Enrichment
Debian DLA
Debian DSA