Junglewise Threat Intelligence

CVE-2026-17747: Google Chrome for Android UI spoofing in Payments

CVE-2026-17747 · Severity: info · CVSS 0 · Published 2026-07-30

Technologies: Google Chrome. Vendors: Google.

Executive brief

Google Chrome for Android contains a security vulnerability in its Payments component. A remote attacker who has already compromised the browser's rendering process could use a specially crafted web page to spoof user interface elements. This could be used to trick users into performing unintended actions or disclosing sensitive information by mimicking legitimate payment prompts.

Technical details

An improper input validation vulnerability (CWE-20) exists in the Payments component of Google Chrome on Android. The flaw allows a remote attacker who has already achieved code execution within a compromised renderer process to perform UI spoofing via a crafted HTML page. This occurs because the browser fails to sufficiently validate input passed to the payment interface, allowing the attacker to manipulate the visual presentation of payment-related dialogs. The vulnerability is addressed in version 151.0.7922.72.

Affected products

  • Google Chrome prior to 151.0.7922.72

Timeline

  • 2026-07-29: patched: Fixed in version 151.0.7922.72
  • 2026-07-30: disclosed: NVD publication date

References

Related threats