Executive brief
A vulnerability in the Payments component of Google Chrome could allow an attacker to perform UI spoofing. This means a malicious website could display deceptive interface elements to trick users into performing unintended actions or disclosing sensitive information. To exploit this, an attacker would first need to compromise the browser's renderer process.
Technical details
An improper input validation vulnerability (CWE-20) exists in the Payments component of Google Chrome. A remote attacker who has already achieved code execution within a compromised renderer process can exploit this flaw by using a specially crafted HTML page. Successful exploitation allows the attacker to perform UI spoofing, potentially misleading the user during payment workflows. The issue is addressed in Google Chrome version 151.0.7922.72.
Affected products
- Google Chrome prior to 151.0.7922.72
Timeline
- 2026-07-29: disclosed
- 2026-07-29: patched
- 2026-07-30: advisory