Impact
The vulnerability is a use‑after‑free flaw in the Payments component of Google Chrome that allows a malicious web page to access freed memory and potentially escape the browser sandbox, enabling the execution of arbitrary code on the host system. This is a high‑severity memory‑management defect, classified under CWE‑416, which can compromise both confidentiality and integrity of the machine if exploited successfully.
Affected Systems
All users running Google Chrome versions prior to 151.0.7922.109 are affected. The issue exists in the stable channel of Chrome and does not affect newer releases released after the mentioned version.
Risk and Exploitability
Because the flaw can be triggered by a crafted HTML page that a user can be tricked into opening, the attack vector is a web‑based remote exploit. Although the EPSS score is not available, the lack of a KEV listing does not diminish the risk posed by this high‑severity flaw; attackers could achieve a sandbox escape relatively easily if the attacker can embed the vulnerable code in a document or web page served to the victim.
OpenCVE Enrichment