Junglewise Threat Intelligence

CVE-2026-11001: Google Chrome UI spoofing in Payments

CVE-2026-11001 · Severity: info · CVSS 5.4 · Published 2026-06-04

Technologies: Google Chrome. Vendors: Google.

Executive brief

A vulnerability in the Payments component of Google Chrome could allow a malicious website to trick users into performing unintended actions. By convincing a user to interact with a specially crafted web page, an attacker can spoof parts of the browser's user interface. This could lead to users being misled about the status of a transaction or the identity of a site, potentially resulting in unauthorized actions or the disclosure of sensitive information.

Technical details

An inappropriate implementation in the Payments component of Google Chrome prior to version 149.0.7827.53 allowed for UI spoofing. A remote attacker could exploit this by hosting a crafted HTML page and convincing a user to perform specific UI gestures. This interaction allows the attacker to misrepresent the browser's interface, potentially bypassing security indicators or misleading the user during a payment flow. The vulnerability is categorized by Chromium as Medium severity and requires user interaction to be successful. Google has addressed this issue in the stable channel update for Windows, Mac, and Linux.

Affected products

  • Google Chrome prior to 149.0.7827.53

Timeline

  • 2026-06-02: patched: Chrome 149.0.7827.53 released to stable channel.
  • 2026-06-04: disclosed: CVE published.

References

Related threats