Impact
Use‑after‑free in the Payments module of Google Chrome on macOS allows a malicious HTML page to trigger a memory error that executes arbitrary code outside the browser sandbox. The bug is a classic double‑free (CWE‑416) flaw that bypasses sandbox isolation, giving an attacker full system‑level access if the page is served to a user. This constitutes a high‑severity remote code execution vulnerability because the attacker can run code with the privileges of the logged‑in user.
Affected Systems
The flaw applies to all macOS installations of Google Chrome whose version is older than 153.0.8010.36. Users running any earlier build use the Payments feature and therefore expose themselves to the risk. The vulnerability is triggered only on macOS; other operating systems are not affected as stated.
Risk and Exploitability
The vulnerability has a very high severity with a CVSS score of 9.6. The EPSS score of <1% indicates a low exploitation probability, but the flaw can be triggered with a simple crafted HTML page that a user visits. Because the payload runs outside the browser sandbox, it provides full system‑level access. The flaw is not listed in the CISA KEV catalog. Early updates mitigate the issue.
OpenCVE Enrichment
Debian DLA
Debian DSA