Impact
A use‑after‑free flaw in the Payments component of Google Chrome allows an attacker to exploit a crafted HTML page, potentially executing code outside the browser sandbox. The vulnerability arises from improper memory handling, enabling arbitrary code execution on the victim’s system and representing a high‑severity risk.
Affected Systems
Google Chrome versions earlier than 153.0.8010.36 are affected. The flaw is tied to the Payments feature and affects any user who visits a maliciously constructed web page using those browser versions.
Risk and Exploitability
The flaw has a CVSS score of 9.6, indicating an extremely high severity; its EPSS score is < 1% and it is not listed in CISA's KEV catalog. The attack vector is inferred to be remote, requiring a victim to open a specially crafted HTML page—likely delivered via social engineering. Exploitation would occur after the use‑after‑free event triggers code execution outside the sandbox, giving the attacker full control of the victim machine. The impact includes confidentiality, integrity, and availability compromise of the affected system.
OpenCVE Enrichment
Debian DLA
Debian DSA