Impact
The vulnerability is a use‑after‑free bug in the Payments module of Google Chrome. It allows an attacker who has already compromised a renderer process to craft a malicious HTML page that may trigger the freed memory use and result in a sandbox escape. This leads to the potential execution of code with higher privileges than the renderer, effectively granting remote code execution capabilities. The weakness corresponds to both CWE‑416, a memory management issue that can be exploited to violate process isolation, and CWE‑825, indicating a lack of security checks for a neutralized resource that can lead to unauthorized use.
Affected Systems
The flaw affects Google Chrome prior to version 151.0.7922.109 on all supported operating systems. Any machine running a vulnerable Chrome version is at risk if the attacker can deliver a crafted HTML page to the compromised renderer.
Risk and Exploitability
The CVSS score is 8.3. Exploitation requires the attacker to already have gained control of a renderer process; thus it is not a pure remote exploit but relies on a prior foothold. The EPSS score is <1% (0.00267), indicating a low but non‑zero probability of exploitation, and the vulnerability is not listed in the CISA KEV catalog. Nonetheless, because a sandbox escape could lead to arbitrary code execution at the machine level, the risk remains significant, especially in environments where renderer compromise is plausible.
OpenCVE Enrichment
Debian DLA
Debian DSA