Executive brief
A security vulnerability exists in the Payments component of Google Chrome, the widely used web browser. An attacker could exploit this flaw by tricking a user into visiting a malicious website and performing specific interactions, potentially leading to unauthorized code execution or a browser crash. This could allow an attacker to compromise the user's system or access sensitive information handled by the browser.
Technical details
A use-after-free (UAF) vulnerability exists in the Payments component of Google Chrome prior to version 150.0.7871.115. The flaw is triggered when the browser attempts to access memory that has already been freed, a condition reachable via a crafted HTML page. Exploitation requires a remote attacker to convince a user to perform specific UI gestures. Successful exploitation can lead to heap corruption, which may allow for arbitrary code execution within the context of the browser process. Google has addressed this issue in the stable channel update to version 150.0.7871.115 for Windows and Mac, and 150.0.7871.114 for Linux.
Affected products
- Google Chrome < 150.0.7871.115
Timeline
- 2026-06-11: disclosed: Reported to Chromium by Google researchers
- 2026-07-08: patched: Fixed in Chrome stable channel update 150.0.7871.115
- 2026-07-08: advisory: NVD publication date