Executive brief
A vulnerability in the Payments component of Google Chrome could allow a malicious website to spoof user interface elements. This could be used to trick users into performing unintended actions or providing sensitive information by displaying deceptive payment-related overlays. Users are advised to update to the latest version of the browser to mitigate this risk.
Technical details
An inappropriate implementation vulnerability exists within the Payments component of Google Chrome. A remote attacker can exploit this flaw by enticing a user to visit a specially crafted HTML page. Successful exploitation allows the attacker to perform UI spoofing, potentially misleading the user during payment workflows. The vulnerability is addressed in Chrome version 149.0.7827.53. Google classifies this as a Low severity issue.
Affected products
- Google Chrome prior to 149.0.7827.53
Timeline
- 2026-06-02: patched: Chrome 149.0.7827.53 released to stable channel
- 2026-06-04: advisory: NVD publication date
- 2026-06-05: disclosed: CVE published in NVD dataset