Junglewise Threat Intelligence

CVE-2026-17955: Google Chrome UI spoofing in Payments

CVE-2026-17955 · Severity: info · Published 2026-07-30

Technologies: Google Chrome. Vendors: Google.

Executive brief

A vulnerability in the Payments component of Google Chrome could allow a malicious website to spoof parts of the browser's user interface. This could be used to trick users into performing unintended actions or providing sensitive information by displaying misleading payment-related prompts. Users are advised to update to the latest version of Chrome to mitigate this risk.

Technical details

An improper input validation vulnerability (CWE-20) exists in the Payments component of Google Chrome. A remote attacker can exploit this by enticing a user to visit a specially crafted HTML page. Successful exploitation allows the attacker to perform UI spoofing, potentially misleading the user during payment workflows. The vulnerability is addressed in Google Chrome version 151.0.7922.72 for Windows, Mac, and Linux.

Affected products

  • Google Chrome prior to 151.0.7922.72

Timeline

  • 2026-07-29: patched: Fixed in version 151.0.7922.72
  • 2026-07-30: disclosed: NVD publication date

References

Related threats