Executive brief
Google Chrome's Payments component contained a vulnerability that could allow a remote attacker to steal sensitive cross-origin data through a malicious HTML page. An attacker could craft a webpage to trick users into visiting it, potentially exposing payment information or other sensitive data stored in the browser from other websites. This vulnerability was patched in Chrome 152.0.7977.65.
Technical details
This is an information leak vulnerability in the Payments component of Google Chrome prior to version 152.0.7977.65. The vulnerability allows a remote attacker to obtain cross-origin data via a crafted HTML page, meaning an attacker can access sensitive information from different websites than the one serving the malicious HTML. No authentication is required and the attack vector is entirely network-based—a user simply needs to visit a malicious webpage in their browser. The vulnerability was fixed in Chrome 152 stable release on August 25, 2026.
Affected products
- Google Chrome prior to 152.0.7977.65
Timeline
- 2026-08-25: disclosed: Fixed in Chrome 152.0.7977.65 stable release
- 2026-08-25: advisory