Junglewise Threat Intelligence

CVE-2026-11019: Google Chrome for Android domain spoofing in Payments

CVE-2026-11019 · Severity: info · CVSS 4.3 · Published 2026-06-04

Technologies: Google Chrome. Vendors: Google.

Executive brief

A vulnerability in Google Chrome for Android could allow a malicious website to misrepresent its identity. By tricking the browser's payment component, an attacker who has already partially compromised the browser's internal processes could display a fake domain name to the user. This could be used to facilitate phishing attacks or deceive users during financial transactions.

Technical details

An inappropriate implementation vulnerability exists in the Payments component of Google Chrome for Android. A remote attacker who has already achieved a compromise of the renderer process can exploit this flaw by enticing a user to visit a specially crafted HTML page. Successful exploitation allows the attacker to perform domain spoofing, potentially misleading the user about the origin of a payment request or transaction. The issue is addressed in Google Chrome version 149.0.7827.53.

Affected products

  • Google Chrome prior to 149.0.7827.53

Timeline

  • 2026-06-02: patched: Chrome 149.0.7827.53 released to stable channel
  • 2026-06-04: disclosed: CVE published

References

Related threats