Junglewise Threat Intelligence

CVE-2026-79042: Google Chrome missing authorization in Payments on Android

CVE-2026-79042 · Severity: medium · CVSS 4.3 · Published 2026-08-25

Technologies: Google Chrome, Google Android. Vendors: Google.

Executive brief

Google Chrome's Payments feature on Android contains a missing authorization vulnerability that allows a remote attacker to bypass system access restrictions through social engineering and a crafted HTML page. This could enable unauthorized payment transactions or access to payment information without proper user consent, potentially leading to financial fraud or data theft.

Technical details

CVE-2026-79042 is a missing authorization vulnerability in the Payments component of Google Chrome on Android prior to version 152.0.7977.65. The vulnerability allows a remote attacker to bypass system access restrictions via social engineering and a crafted HTML page. The attack requires user interaction (social engineering) and network reachability. An attacker can leverage this to perform unauthorized actions related to payment processing without proper authorization checks. The vulnerability was patched in Chrome 152.0.7977.65 and later versions.

Affected products

  • Google Chrome prior to 152.0.7977.65 on Android

Timeline

  • 2026-08-25: disclosed: CVE-2026-79042 disclosed; Chrome 152.0.7977.65 released with fix

References

Related threats