Description
Information leak in Payments in Google Chrome prior to 155.0.8059.39 allowed a remote attacker to obtain cross-origin data via a crafted HTML page. (Chromium security severity: Medium)
Published: 2026-10-06
Score: 4.3 Medium
EPSS: n/a
KEV: No
Impact: Cross‑Origin Payment Data Leak
Action: Update Chrome
AI Analysis

Impact

The vulnerability allows a remote attacker to obtain cross‑origin data from the Payments subsystem in Chrome before version 155.0.8059.39. This results in leakage of potentially sensitive user data such as payment information and other content that was not intended to be exposed. The flaw is categorized as an information disclosure (CWE‑200) and could compromise user privacy and data integrity if the attacker has prior domain control.

Affected Systems

Google Chrome browsers with versions older than 155.0.8059.39 in the stable channel are affected. The issue was fixed in the subsequent releases as documented by Google. Users running the above versions should update to the latest stable release.

Risk and Exploitability

The attack vector is remote and triggered by serving a specially crafted HTML page to a victim's browser. The vulnerability was rated Medium severity by Chromium. The EPSS score is unavailable, and it is not listed in the CISA KEV catalog, suggesting no active exploitation reports. Nonetheless, an attacker could exploit the flaw by hosting a malicious site that serves payment scripts, extracting information from other origins the victim visited. The absence of a public exploit does not eliminate risk, especially for organizations that run Chrome in environments with sensitive payment data.

Generated by OpenCVE AI on October 6, 2026 at 22:07 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade Google Chrome to version 155.0.8059.39 or newer to apply the vendor’s fix.
  • Disable or restrict the Payments API for untrusted sites using Chrome policy settings or extensions to limit exposure.
  • Monitor user sessions for anomalous payment‑related requests and enforce least privilege on application code that interacts with the Payments service.

Generated by OpenCVE AI on October 6, 2026 at 22:07 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 06 Oct 2026 22:30:00 +0000

Type Values Removed Values Added
Title Cross‑Origin Payment Data Leak via Crafted HTML Page
Metrics cvssV3_1

{'score': 4.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 06 Oct 2026 19:00:00 +0000

Type Values Removed Values Added
Description Information leak in Payments in Google Chrome prior to 155.0.8059.39 allowed a remote attacker to obtain cross-origin data via a crafted HTML page. (Chromium security severity: Medium)
Weaknesses CWE-200
References

Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: Chrome

Published:

Updated: 2026-10-06T21:16:15.808Z

Reserved: 2026-10-06T16:36:28.865Z

Link: CVE-2026-106360

cve-icon Vulnrichment

Updated: 2026-10-06T21:11:15.632Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-10-06T19:18:04.960

Modified: 2026-10-06T22:17:03.630

Link: CVE-2026-106360

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-06T22:15:06Z

Weaknesses
  • CWE-200

    Exposure of Sensitive Information to an Unauthorized Actor