Executive brief
A security issue in Google Chrome for Android could allow a malicious website to access sensitive information stored in the browser's memory. This occurs due to a flaw in how the browser handles payment-related data. An attacker would need to trick a user into visiting a specially crafted webpage to exploit this vulnerability.
Technical details
An information disclosure vulnerability exists in the Payments component of Google Chrome for Android due to insufficient policy enforcement. A remote attacker can exploit this by hosting a specially crafted HTML page and inducing a user to visit it. Successful exploitation allows the attacker to read sensitive information from the browser's process memory. This issue is addressed in Google Chrome version 150.0.7871.47 and later.
Affected products
- Google Chrome prior to 150.0.7871.47
Timeline
- 2026-06-30: disclosed
- 2026-06-30: patched