Executive brief
A security vulnerability exists in the Payments component of Google Chrome, the widely used web browser. By tricking a user into visiting a specially crafted website, an attacker could cause the browser to crash or potentially execute unauthorized code. This could lead to the theft of sensitive information or full compromise of the user's computer.
Technical details
A use-after-free (UAF) vulnerability exists in the Payments component of Google Chrome prior to version 149.0.7827.103. The flaw is triggered when the browser incorrectly manages memory during payment processing operations. A remote, unauthenticated attacker can exploit this by enticing a user to visit a malicious HTML page, leading to heap corruption. Successful exploitation could allow for arbitrary code execution within the context of the browser's sandbox or cause a denial-of-service (DoS) condition. Google has addressed this in the stable channel update for Windows, Mac, and Linux.
Affected products
- Google Chrome prior to 149.0.7827.103
Timeline
- 2026-05-16: disclosed: Reported by Google internal researchers
- 2026-06-08: patched: Fixed in version 149.0.7827.103
- 2026-06-09: advisory: NVD publication date