Impact
A use‑after‑free flaw in the Payments module of Google Chrome allows a remote attacker to potentially execute arbitrary code outside the browser sandbox via a crafted HTML page. This high‑severity weakness can give attackers full control over the victim’s system.
Affected Systems
All desktop builds of Google Chrome older than version 153.0.8010.36 on Windows, macOS, and Linux are vulnerable. The flaw resides in the Payments component and cannot be exploited in later releases.
Risk and Exploitability
An EPSS score of <1% indicates a low but non-zero exploitation probability, and the vulnerability is not listed in the CISA KEV catalog. The CVSS score of 9.6 reflects a high severity. The likely attack vector is a remote attacker serving a malicious HTML page to a user who opens it in the affected browser. The attacker could break out of the sandbox and execute code independently of the browser process, leading to compromise of the host machine.
OpenCVE Enrichment
Debian DLA
Debian DSA