Junglewise Threat Intelligence

CVE-2026-8566: Google Chrome for Android DAC bypass in Payments

CVE-2026-8566 · Severity: medium · CVSS 4.3 · Published 2026-05-14

Technologies: Google Chrome, Google Android. Vendors: Google.

Executive brief

A vulnerability in the Payments component of Google Chrome for Android could allow a malicious website to bypass security controls. By tricking a user into visiting a specially crafted webpage, an attacker could potentially interfere with payment-related policies or access restricted information. This could lead to unauthorized actions within the browser's payment interface or a breach of user privacy.

Technical details

An insufficient policy enforcement vulnerability exists in the Payments component of Google Chrome for Android. The flaw allows a remote attacker to bypass discretionary access control (DAC) mechanisms by enticing a user to visit a maliciously crafted HTML page. This is a medium-severity issue that stems from improper validation of security policies within the payment processing workflow. An exploit could allow an attacker to perform actions that should be restricted by the browser's security model. The issue is resolved in version 148.0.7778.168.

Affected products

  • Google Chrome prior to 148.0.7778.168

Timeline

  • 2025-12-21: disclosed: Reported by Jorian Woltjer
  • 2026-05-12: patched: Fixed in Chrome Stable channel update 148.0.7778.168
  • 2026-05-14: advisory: NVD publication date

References

Related threats