Use after free in Payments in Google Chrome prior to 90.0.4430.212 allowed an attacker who convinced a user to install a malicious payments app to potentially exploit heap corruption via a crafted HTML page.
No PoCs from references.
- https://github.com/ARPSyndicate/cvemon
- https://github.com/BOB-Jour/Chromium-Bug-Hunting-Project