Junglewise Threat Intelligence

CVE-2026-87615: Google Chrome race condition in Payments UI spoofing

CVE-2026-87615 · Severity: medium · CVSS 5.4 · Published 2026-09-09

Technologies: Google Chrome. Vendors: Google.

Executive brief

Google Chrome's payment processing component contains a race condition flaw that allows attackers to spoof critical user interface elements through a crafted web page combined with social engineering. This could trick users into confirming fraudulent payment transactions or entering sensitive financial information into attacker-controlled fields, compromising payment security and customer trust.

Technical details

A race condition vulnerability exists in Chrome's Payments implementation prior to version 153.0.8010.36. The flaw allows a remote attacker to spoof UI elements via a crafted HTML page, combined with social engineering tactics to manipulate user actions. The vulnerability requires user interaction (visiting a malicious page and interacting with the spoofed UI). An attacker could deceive users into authorizing unauthorized payments or revealing sensitive financial data. The fix is available in Chrome 153.0.8010.36 and later versions.

Affected products

  • Google Chrome prior to 153.0.8010.36

Timeline

  • 2026-09-09: disclosed
  • 2026-09-08: patched: Chrome 153.0.8010.36 released

References

Related threats