Executive brief
A vulnerability in the Payments component of Google Chrome for Android could allow a malicious website to access data from other websites. This occurs when a user visits a specially crafted HTML page, potentially leading to the unauthorized disclosure of sensitive information across different web origins. Google has released an update to address this issue.
Technical details
An inappropriate implementation vulnerability exists in the Payments component of Google Chrome for Android prior to version 149.0.7827.53. A local attacker can exploit this by enticing a user to visit a specially crafted HTML page, which triggers a cross-origin data leak. This bypasses the Same-Origin Policy (SOP) protections intended to keep data from different websites isolated. The vulnerability is classified by Chromium as Medium severity. Users should update to version 149.0.7827.53 or later to mitigate this risk.
Affected products
- Google Chrome prior to 149.0.7827.53
Timeline
- 2026-06-02: patched: Chrome 149.0.7827.53 released to stable channel
- 2026-06-04: disclosed: CVE published and NVD record created