Impact
The vulnerability is a use‑after‑free flaw in the Payments component of Google Chrome that allows a malicious web page to access freed memory and potentially escape the browser sandbox, enabling the execution of arbitrary code on the host system. This is a high‑severity memory‑management defect, classified under CWE‑416 and CWE‑825, which can compromise both confidentiality and integrity of the machine if exploited successfully.
Affected Systems
All users running Google Chrome versions prior to 151.0.7922.109 are affected. The issue exists in the stable channel of Chrome and does not affect newer releases released after the mentioned version.
Risk and Exploitability
Because the flaw can be triggered by a crafted HTML page that a user can be tricked into opening, the attack vector is a web‑based remote exploit. The CVSS score is 9.6, indicating a critical level of severity. The EPSS score is <1%, suggesting a low probability of exploitation in the current landscape, but the low probability does not diminish the high potential impact; attackers could achieve a sandbox escape relatively easily if the attacker can embed the vulnerable code in a document or web page served to the victim.
OpenCVE Enrichment
Debian DLA
Debian DSA