Junglewise Threat Intelligence

CVE-2026-87635: Google Chrome UI misrepresentation in Payments

CVE-2026-87635 · Severity: medium · CVSS 5.4 · Published 2026-09-09

Technologies: Google Chrome. Vendors: Google.

Executive brief

Google Chrome's Payments UI component was vulnerable to spoofing attacks, allowing malicious websites to display fake payment interface elements to deceive users. An attacker could craft a webpage to mimic legitimate payment dialogs, potentially tricking users into entering sensitive payment information or authorizing fraudulent transactions.

Technical details

This vulnerability is a UI misrepresentation flaw in Chrome's Payments component, where insufficient validation of HTML content allowed remote attackers to craft malicious pages that could spoof or mask legitimate payment UI elements. The attack is network-based and requires user interaction (visiting a crafted webpage); no authentication is required. An attacker can deceive users into believing they are interacting with legitimate payment prompts when in fact they are viewing attacker-controlled content. The vulnerability was fixed in Chrome 153.0.8010.36 and later versions.

Affected products

  • Google Chrome prior to 153.0.8010.36

Timeline

  • 2026-09-09: disclosed
  • 2026-09-08: patched: Chrome 153.0.8010.36 released

References

Related threats