Описание
Use after free in Payments in Google Chrome prior to 151.0.7922.109 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)
A flaw was found in Chromium. This use-after-free vulnerability in the Payments component could allow a remote attacker, who has already compromised the renderer process, to potentially escape the browser's security sandbox. This could be achieved by enticing a user to visit a specially crafted HTML page.
Отчет
This Important flaw in Chromium's Payments component allows a remote attacker to potentially escape the browser's sandbox after compromising the renderer process. This elevated impact stems from the ability to bypass security boundaries, which could lead to further system compromise, even though it requires a prior successful exploit of the renderer.
Меры по смягчению последствий
To reduce the risk of exploitation, users should avoid visiting untrusted or suspicious websites. Additionally, employing browser sandboxing mechanisms can help contain potential compromises.
Дополнительная информация
Статус:
EPSS
9 Critical
CVSS3
Связанные уязвимости
Use after free in Payments in Google Chrome prior to 151.0.7922.109 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)
Use after free in Payments in Google Chrome prior to 151.0.7922.109 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)
Use after free in Payments in Google Chrome prior to 151.0.7922.109 al ...
Use after free in Payments in Google Chrome prior to 151.0.7922.109 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)
EPSS
9 Critical
CVSS3