Junglewise Threat Intelligence

CVE-2026-11245: Google Chrome UI spoofing in Payments

CVE-2026-11245 · Severity: info · CVSS 0 · Published 2026-06-05

Technologies: Google Chrome. Vendors: Google.

Executive brief

A vulnerability in the Payments component of Google Chrome could allow a malicious website to spoof user interface elements. This could be used to trick users into performing unintended actions or providing sensitive information by displaying deceptive payment-related overlays. Users are advised to update to the latest version of the browser to mitigate this risk.

Technical details

An inappropriate implementation vulnerability exists within the Payments component of Google Chrome. A remote attacker can exploit this flaw by enticing a user to visit a specially crafted HTML page. Successful exploitation allows the attacker to perform UI spoofing, potentially misleading the user during payment workflows. The vulnerability is addressed in Chrome version 149.0.7827.53. Google classifies this as a Low severity issue.

Affected products

  • Google Chrome prior to 149.0.7827.53

Timeline

  • 2026-06-02: patched: Chrome 149.0.7827.53 released to stable channel
  • 2026-06-04: advisory: NVD publication date
  • 2026-06-05: disclosed: CVE published in NVD dataset

References

Related threats