Executive brief
A security vulnerability was identified in the Payments component of Google Chrome. This flaw could allow a malicious website to bypass security boundaries and access data from other websites the user has open. If exploited, this could lead to the unauthorized disclosure of sensitive user information.
Technical details
An insufficient policy enforcement vulnerability exists in the Payments component of Google Chrome. The flaw allows a remote attacker to bypass Same-Origin Policy (SOP) protections by enticing a user to visit a specially crafted HTML page. Successful exploitation enables the attacker to leak sensitive data across origins. The vulnerability is addressed in Chrome version 151.0.7922.72. Chromium developers have assigned this a severity rating of Medium.
Affected products
- Google Chrome prior to 151.0.7922.72
Timeline
- 2026-07-29: patched: Fixed in Chrome Stable channel update 151.0.7922.72
- 2026-07-30: disclosed: NVD publication date