Executive brief
Chrome's payment and transaction processing platform contains an authorization bypass vulnerability that allows an attacker who has already compromised a webpage's rendering process to bypass security boundaries and access payment data. This could enable attackers to steal payment information, redirect transactions, or manipulate financial operations if they gain initial access through malicious websites or browser exploits.
Technical details
An incorrect authorization flaw exists in the Transactions Platform component of Google Chrome versions prior to 152.0.7977.65. The vulnerability requires an attacker to first compromise the renderer process (the sandboxed component that executes website code), after which they can bypass web origin policy restrictions via a crafted HTML page. This is a post-compromise escalation: while it does not directly gain initial access, it allows an already-compromised process to violate security boundaries and access resources from other origins. The fix is available in Chrome 152.0.7977.65 and later.
Affected products
- Google Chrome prior to 152.0.7977.65
Timeline
- 2026-08-25: disclosed
- 2026-08-25: patched: Fixed in Chrome 152.0.7977.65