Executive brief
Google Chrome's Payments UI component was vulnerable to spoofing attacks, allowing malicious websites to display fake payment interface elements to deceive users. An attacker could craft a webpage to mimic legitimate payment dialogs, potentially tricking users into entering sensitive payment information or authorizing fraudulent transactions.
Technical details
This vulnerability is a UI misrepresentation flaw in Chrome's Payments component, where insufficient validation of HTML content allowed remote attackers to craft malicious pages that could spoof or mask legitimate payment UI elements. The attack is network-based and requires user interaction (visiting a crafted webpage); no authentication is required. An attacker can deceive users into believing they are interacting with legitimate payment prompts when in fact they are viewing attacker-controlled content. The vulnerability was fixed in Chrome 153.0.8010.36 and later versions.
Affected products
- Google Chrome prior to 153.0.8010.36
Timeline
- 2026-09-09: disclosed
- 2026-09-08: patched: Chrome 153.0.8010.36 released