Executive brief
A vulnerability in the Payments component of Google Chrome could allow a malicious website to access data from other websites. This occurs when a user visits a specially crafted webpage, potentially leading to the unauthorized disclosure of sensitive information across different web domains. Google has released an update to address this issue in the latest version of the Chrome browser.
Technical details
An inappropriate implementation vulnerability exists within the Payments component of Google Chrome. A remote attacker can exploit this flaw by enticing a user to visit a maliciously crafted HTML page. Successful exploitation allows the attacker to bypass cross-origin isolation and leak data from other origins. The vulnerability is addressed in Chrome version 151.0.7922.72 for Windows, Mac, and Linux. Chromium developers have assigned this a security severity of Medium.
Affected products
- Google Chrome prior to 151.0.7922.72
Timeline
- 2026-07-29: patched: Stable Channel Update for Desktop released
- 2026-07-30: disclosed: NVD publication date