Junglewise Threat Intelligence

CVE-2026-91739: Google Chrome missing authorization in Transactions Platform

CVE-2026-91739 · Severity: medium · CVSS 4.2 · Published 2026-09-15

Technologies: Google Chrome. Vendors: Google.

Executive brief

Google Chrome's Transactions Platform contained a missing authorization check that could allow an attacker with control of the browser's renderer process to spoof user interface elements through a malicious webpage. An attacker exploiting this flaw could deceive users into performing unintended actions or disclosing sensitive information by crafting fake payment or transaction dialogs.

Technical details

This vulnerability is a missing authorization flaw in Chrome's Transactions Platform component. The affected versions prior to 153.0.8010.47 failed to properly validate authorization when displaying UI elements, allowing a compromised renderer process to spoof legitimate interface components. The attack requires the renderer process to be compromised first, which could occur via other browser vulnerabilities or malicious website code. An attacker can craft a malicious HTML page that, once the renderer is compromised, triggers spoofed UI elements to deceive users. Google has patched this issue in Chrome 153.0.8010.47 and later versions.

Affected products

  • Google Chrome before 153.0.8010.47

Timeline

  • 2026-09-15: disclosed
  • 2026-09-15: patched: Fixed in Chrome 153.0.8010.47

References

Related threats